to prioritize threats based on their likelihood and impact. The approach is represented by an acronym “DREAD” which stands for: Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Each of these factors is ranked on a scale of 0-10, and the sum of these values helps to determine the overall risk. Higher values indicate greater risk, requiring immediate mitigation strategies.
to have occurred Non-sensitive user data has been compromised Non-sensitive administrative data has been compromised The entire information system has been destroyed. All data and applications are inaccessible 0 5 8 9 10 practical-devsecops.com | #CertifiedThreatModelingProfessional Damage potential is the amount of damage that a threat actor can cause, and is measured on the following scale: Damage potential
Easy to replicate the attack Very easy to replicate the attack 0 5 0.75 10 practical-devsecops.com | #CertifiedThreatModelingProfessional Reproducibility indicates if it’s simple to replicate an attack. These are again plotted on a scale of 0 – 10. Reproducibility
the vulnerability Available attack tools needed to exploit the vulnerability Web application proxies are needed to exploit the vulnerability Indicates the requirement of a web browser needed to exploit the vulnerability 2.5 5 9 10 practical-devsecops.com | #CertifiedThreatModelingProfessional Different organizational vulnerabilities can be exploited by using different tools and skills, as indicated by their ratings. They are rated as follows: Exploitability
Few users affected Administrative users affected 0 1.5 6 8 practical-devsecops.com | #CertifiedThreatModelingProfessional Calculate the number of users who will be affected by an attack to determine the potential impact of the attack. This is again rated on a scale of 1 – 10. Affected Users All users affected 10
the vulnerability Available attack tools needed to exploit the vulnerability Web application proxies are needed to exploit the vulnerability Indicates the requirement of a web browser needed to exploit the vulnerability 2.5 5 9 10 practical-devsecops.com | #CertifiedThreatModelingProfessional Different organizational vulnerabilities can be exploited by using different tools and skills, as indicated by their ratings. They are rated as follows: Exploitability
uncover the vulnerability Vulnerability found in the public domain Vulnerability found in web address bar or form 0 5 8 10 practical-devsecops.com | #CertifiedThreatModelingProfessional On a scale of 1 – 10, this factor rates the discoverability of a vulnerability. Discoverability