Home Technical Support DREAD and OWASP Risk Rating: Scoring Threats in Threat Modeling Exercises

DREAD and OWASP Risk Rating: Scoring Threats in Threat Modeling Exercises

Last updated on Sep 08, 2026

DREAD and OWASP Risk Rating: Scoring Threats in Threat Modeling Exercises

After identifying threats with STRIDE, you need to prioritize them. The DREAD model and the OWASP Risk Rating Methodology are the two scoring frameworks taught across the Security Champion and Threat Modeling Professional courses. This article covers how each model works and how to apply them in the hands-on exercises.


Table of Contents

  1. DREAD Risk Model
  2. OWASP Risk Rating Methodology Overview
  3. Likelihood Scoring
  4. Impact Scoring
  5. Calculating Final Risk
  6. StrideGPT Exercise: DREAD in Practice
  7. Common Failure Modes in the Risk Rating Lab
  8. Common Questions

DREAD Risk Model

DREAD is a legacy risk scoring model. Each dimension is scored from 1-10, and the scores are summed:

Letter Dimension Question
D Damage How much damage can this threat cause?
R Reproducibility How easy is it to reproduce the attack?
E Exploitability How easy is it to exploit?
A Affected Users How many users are affected?
D Discoverability How easy is it to discover this vulnerability?

Total score range: 5-50

Note: DREAD is considered outdated by modern standards. The exercises teach it for historical context but recommend OWASP Risk Rating Methodology for actual use.


OWASP Risk Rating Methodology Overview

The Formula

Risk = Average(Likelihood, Impact)

Risk is banded into three levels:

Risk Score Band
0-3 Low
3-6 Medium
6-9 High

The methodology separates scoring into Likelihood of Exploitation and Impact, each with multiple sub-factors.

Reference: OWASP Risk Rating Methodology

Online calculator: OWASP Calculator


Likelihood Scoring

Threat Agent Factors

How likely is the threat to be exploited? Scored 1-9 based on attacker characteristics:

Factor Low (1) Medium (4) High (9)
Skill Level Casual surfer Script kiddie Skilled hacker
Motive None Low (curiosity) High (financial gain)
Opportunity No access Some access Full access
Size Single attacker Small group Large organization

Vulnerability Factors

How exploitable is the vulnerability?

Factor Low Medium High
Ease of Discovery 1 3 7-9
Ease of Exploit 1 3 5-9
Awareness 1 (not aware) 4 (some) 6-9 (well known)
Intrusion Detection 1 (hard to detect) 3 8-9 (easy to detect)

Likelihood = Average of all 8 factors


Impact Scoring

Technical Impact

Damage to security properties:

Factor Description
Loss of Confidentiality Data exposure
Loss of Integrity Data tampering
Loss of Availability Service disruption
Loss of Accountability Audit trail destroyed

Business Impact

Real-world consequences:

Factor Description
Financial Damage Direct monetary loss
Reputation Damage Brand trust erosion
Non-Compliance Regulatory violations (PCI, GDPR)
Privacy Violation Personal data exposure

Impact = Average of technical and business impact scores


Calculating Final Risk

Putting It Together

Likelihood = Average(8 threat agent + vulnerability factors)
Impact = Average(technical + business impact factors)
Risk = Average(Likelihood, Impact)

Example from the exercise: A spoofing threat against the password reset workflow might score:

  • Likelihood: 5.5 (moderate skill attacker, some opportunity, known vulnerability)
  • Impact: 6.0 (confidentiality loss, some financial damage)
  • Risk: 5.75 → Medium band

Risk Treatment Options

Once scored, each risk has a treatment:

Action When
Fix High risk, low cost to remediate
Mitigate High risk, add controls to reduce score
Accept Low risk, or cost of fix exceeds impact
Transfer Insurance, third-party handling

Key concept: Not all risks are worth fixing. Cost-benefit analysis matters.


StrideGPT Exercise: DREAD in Practice

The StrideGPT Hands-On Lab

The Threat Modeling with StrideGPT exercise (available in Threat Modeling, AI Security, and MCP Security courses) uses an AI tool to automatically generate STRIDE threats and DREAD scores.

Machine: devsecops-box-gpu

Key Commands

git clone https://github.com/mrwadams/stride-gpt.git
cd stride-gpt
git checkout 9e70871959c0e88ef5ab1afbf654f0c294968ea6
python3 -m venv .venv
source .venv/bin/activate
uv pip install -r requirements.txt
uv pip install 'mistralai>=1.0,<2'
cp .env.example .env

Ollama Setup

systemctl start ollama
ollama pull phi
ollama list
curl http://localhost:11434/api/tags

Common StrideGPT Errors

pip stops on blinker (Distutils Error): Means pip is using system Python instead of the project venv. Re-activate the venv and re-run pip install.

502 Bad Gateway in browser while curl on the VM succeeds: Streamlit binding issue. Ensure .streamlit/config.toml has server.address = "0.0.0.0".

Non-deterministic LLM output: StrideGPT results vary between runs due to inherent LLM randomness. This is expected behavior.

DREAD Scoring Output

StrideGPT generates a DREAD score table for each identified threat. Compare the model's rankings with your own sense of business impact — the exercise is designed to build intuition about risk prioritization.


Common Failure Modes in the Risk Rating Lab

Subjectivity in Scoring

Different raters will assign different scores to the same threat. This is normal and expected.

Practical guidance: Timebox scoring discussions. Disagree but commit. The value is in the discussion, not the exact number.

Getting Tangled in Likelihood Discussions

It's easy to spend too much time debating whether a threat agent's skill level is a 4 or a 7.

Fix: Use the scoring tables as guides, not precise instruments. The risk banding (Low/Medium/High) is more useful than the exact score.

Terminal Not Needed

The Rating Risks with OWASP Risk Rating Methodology exercise is conceptual — no terminal commands are required. Use the OWASP online calculator and reference material instead.


Common Questions

Question Answer
Is DREAD still used in industry? DREAD is largely legacy. OWASP Risk Rating Methodology and FAIR are preferred today. DREAD is taught for historical context.
Do I need exact scores for the exercise? No. The exercise focuses on understanding the scoring process and risk banding, not achieving a specific number.
What if my scores differ from the example? That's fine. Risk scoring is subjective. The discussion and reasoning matter more than the exact values.
StrideGPT gives different results each time. Expected. LLM output is non-deterministic. Focus on the categories of threats identified, not exact scores.
The StrideGPT app shows 502 Bad Gateway. Check .streamlit/config.toml has server.address = "0.0.0.0". Ensure the venv is activated.
pip install fails with Distutils Error. Your venv isn't active. Run source .venv/bin/activate and retry.

Wrap-Up

Risk rating turns identified threats into actionable priorities. Key takeaways:

  • DREAD is a simple 5-dimension model (Damage, Reproducibility, Exploitability, Affected Users, Discoverability). Legacy but useful for learning.
  • OWASP Risk Rating is more detailed: 8 factors for likelihood, technical + business impact, averaged to get a risk score banded as Low/Medium/High.
  • Not all risks need fixing. Cost-benefit analysis and business context determine treatment.
  • StrideGPT automates STRIDE threat identification and DREAD scoring using a local LLM.
  • The OWASP Risk Rating exercise is conceptual — no terminal commands needed.

For the StrideGPT lab, remember: devsecops-box-gpu machine, activate the venv, start Ollama, and expect non-deterministic LLM output.