Software security has become more and more critical as we are increasingly depending on the Internet an untrustworthy computing environment. Software functionality and security are tightly related to each other vulnerabilities due to design errors inconsistencies incompleteness and missing constraints in system specifications can be wrongly exploited by security attacks. These two concerns however are often handled separately. In this paper we present a threat driven approach that improves on the quality of software through the realization of a more secure functional model. The approach introduces systematic transformation rules and integration steps for mapping attack tree representations into lower level dynamic behavior then integrates this behavior into statechart-based functional models. Through the focus on both the functional and threat behavior software engineers can introduce clearly define and understand security concerns as software is designed. To identify vulnerabilities our approach then applies security analysis and threat identification to the integrated model.