In this paper, an extended model for attack tree, called attack protection tree, is presented. The traditional attack trees threat model is extended with protection actions on the leaf nodes to protect the intermediate nodes from malicious attack. The proposed formalism allows the protection actions to be defined at the leaf nodes, by doing so, eliminating the chances of attack(s) being successful through ORrefinement. The concepts are illustrated through examples and we use a model checker for attack protection tree analyses.