Salam Imran Bahi,
What is DREAD?
It assesses threats based on five factors: Damage potential, Reproducibility, Exploitability,
Affected users, and Discoverability. Each factor is rated on a scale of 0 to 10, and the overall
threat score is calculated.
Please read the details if interested in reading research articles:
[Link]
[Link]
I find following is one of best article to read and understand the DREAD
[Link]
Step 1:
For each threat to model, we need following parameters:
Threat Description: A brief description or name of the threat.
Damage Potential (0-10): On a scale of 0 to 10, rate the potential damage or impact if the
threat were to materialize. A higher score indicates greater potential damage.
Reproducibility (0-10): Rate the ease with which the threat can be reproduced or repeated.
A higher score means it is easier to reproduce.
Exploitability (0-10): Rate the ease with which an attacker can exploit the vulnerability
associated with the threat. A higher score indicates easier exploitation.
Affected Users (0-10): Rate the number of users or systems that could be affected by the
threat. A higher score means a larger impact on users.
Discoverability (0-10): Rate the ease with which the threat can be discovered or detected. A
higher score indicates easier discoverability.
Step 2:
Need to create an excel document:
Damage Potential Reproducibility (0- Exploitability (0- Affected Users Discoverability (0-
Threat (0-10) 10) 10) (0-10) 10)
Let me take few examples of threats
1. Unauthorized Access | 8 | 7 | 9 | 9 | 6
2. Denial of Service (DoS) | 7 | 8 | 7 | 8 | 6
3. Cross-Site Scripting (XSS) | 6 | 8 | 8 | 7 | 6
4. Data Breach | 9 | 6 | 8 | 9 | 5
5. Phishing Attacks | 7 | 9 | 8 | 8 | 7
6. Malware Infection | 8 | 7 | 9 | 9 | 6
7. Information Disclosure | 6 | 9 | 7 | 7 | 8
Step 3: You can add these weights in excel document:
Assign weights: Assign a weight to each factor based on its importance to your organization
or system. For example, you can assign a weight of 0.4 to Damage Potential, 0.3 to
Exploitability, 0.2 to Affected Users, and 0.1 to Reproducibility and Discoverability. Adjust the
weights based on your specific requirements and priorities.
Step 4:
Multiply and sum: Multiply each factor's score by its assigned weight, and then sum the
weighted scores. This will give you the risk score for each threat.
Myself (Qamar) and many other risk professional prefer to use Multiply over sum.
Step 5:
Rank the risks: Sort the threats based on their risk scores in descending order.
Step 6:
Decide the cut of Risk score to accept as we cannot or will not treat the risk based on ROI
(and Risk based approach)