DREAD and OWASP Risk Rating: Scoring Threats in Threat Modeling Exercises
After identifying threats with STRIDE, you need to prioritize them. The DREAD model and the OWASP Risk Rating Methodology are the two scoring frameworks taught across the Security Champion and Threat Modeling Professional courses. This article covers how each model works and how to apply them in the hands-on exercises.
Table of Contents
- DREAD Risk Model
- OWASP Risk Rating Methodology Overview
- Likelihood Scoring
- Impact Scoring
- Calculating Final Risk
- StrideGPT Exercise: DREAD in Practice
- Common Failure Modes in the Risk Rating Lab
- Common Questions
DREAD Risk Model
DREAD is a legacy risk scoring model. Each dimension is scored from 1-10, and the scores are summed:
| Letter | Dimension | Question |
|---|---|---|
| D | Damage | How much damage can this threat cause? |
| R | Reproducibility | How easy is it to reproduce the attack? |
| E | Exploitability | How easy is it to exploit? |
| A | Affected Users | How many users are affected? |
| D | Discoverability | How easy is it to discover this vulnerability? |
Total score range: 5-50
Note: DREAD is considered outdated by modern standards. The exercises teach it for historical context but recommend OWASP Risk Rating Methodology for actual use.
OWASP Risk Rating Methodology Overview
The Formula
Risk = Average(Likelihood, Impact)
Risk is banded into three levels:
| Risk Score | Band |
|---|---|
| 0-3 | Low |
| 3-6 | Medium |
| 6-9 | High |
The methodology separates scoring into Likelihood of Exploitation and Impact, each with multiple sub-factors.
Reference: OWASP Risk Rating Methodology
Online calculator: OWASP Calculator
Likelihood Scoring
Threat Agent Factors
How likely is the threat to be exploited? Scored 1-9 based on attacker characteristics:
| Factor | Low (1) | Medium (4) | High (9) |
|---|---|---|---|
| Skill Level | Casual surfer | Script kiddie | Skilled hacker |
| Motive | None | Low (curiosity) | High (financial gain) |
| Opportunity | No access | Some access | Full access |
| Size | Single attacker | Small group | Large organization |
Vulnerability Factors
How exploitable is the vulnerability?
| Factor | Low | Medium | High |
|---|---|---|---|
| Ease of Discovery | 1 | 3 | 7-9 |
| Ease of Exploit | 1 | 3 | 5-9 |
| Awareness | 1 (not aware) | 4 (some) | 6-9 (well known) |
| Intrusion Detection | 1 (hard to detect) | 3 | 8-9 (easy to detect) |
Likelihood = Average of all 8 factors
Impact Scoring
Technical Impact
Damage to security properties:
| Factor | Description |
|---|---|
| Loss of Confidentiality | Data exposure |
| Loss of Integrity | Data tampering |
| Loss of Availability | Service disruption |
| Loss of Accountability | Audit trail destroyed |
Business Impact
Real-world consequences:
| Factor | Description |
|---|---|
| Financial Damage | Direct monetary loss |
| Reputation Damage | Brand trust erosion |
| Non-Compliance | Regulatory violations (PCI, GDPR) |
| Privacy Violation | Personal data exposure |
Impact = Average of technical and business impact scores
Calculating Final Risk
Putting It Together
Likelihood = Average(8 threat agent + vulnerability factors)
Impact = Average(technical + business impact factors)
Risk = Average(Likelihood, Impact)
Example from the exercise: A spoofing threat against the password reset workflow might score:
- Likelihood: 5.5 (moderate skill attacker, some opportunity, known vulnerability)
- Impact: 6.0 (confidentiality loss, some financial damage)
- Risk: 5.75 → Medium band
Risk Treatment Options
Once scored, each risk has a treatment:
| Action | When |
|---|---|
| Fix | High risk, low cost to remediate |
| Mitigate | High risk, add controls to reduce score |
| Accept | Low risk, or cost of fix exceeds impact |
| Transfer | Insurance, third-party handling |
Key concept: Not all risks are worth fixing. Cost-benefit analysis matters.
StrideGPT Exercise: DREAD in Practice
The StrideGPT Hands-On Lab
The Threat Modeling with StrideGPT exercise (available in Threat Modeling, AI Security, and MCP Security courses) uses an AI tool to automatically generate STRIDE threats and DREAD scores.
Machine: devsecops-box-gpu
Key Commands
git clone https://github.com/mrwadams/stride-gpt.git
cd stride-gpt
git checkout 9e70871959c0e88ef5ab1afbf654f0c294968ea6
python3 -m venv .venv
source .venv/bin/activate
uv pip install -r requirements.txt
uv pip install 'mistralai>=1.0,<2'
cp .env.example .env
Ollama Setup
systemctl start ollama
ollama pull phi
ollama list
curl http://localhost:11434/api/tags
Common StrideGPT Errors
pip stops on blinker (Distutils Error): Means pip is using system Python instead of the project venv. Re-activate the venv and re-run pip install.
502 Bad Gateway in browser while curl on the VM succeeds: Streamlit binding issue. Ensure .streamlit/config.toml has server.address = "0.0.0.0".
Non-deterministic LLM output: StrideGPT results vary between runs due to inherent LLM randomness. This is expected behavior.
DREAD Scoring Output
StrideGPT generates a DREAD score table for each identified threat. Compare the model's rankings with your own sense of business impact — the exercise is designed to build intuition about risk prioritization.
Common Failure Modes in the Risk Rating Lab
Subjectivity in Scoring
Different raters will assign different scores to the same threat. This is normal and expected.
Practical guidance: Timebox scoring discussions. Disagree but commit. The value is in the discussion, not the exact number.
Getting Tangled in Likelihood Discussions
It's easy to spend too much time debating whether a threat agent's skill level is a 4 or a 7.
Fix: Use the scoring tables as guides, not precise instruments. The risk banding (Low/Medium/High) is more useful than the exact score.
Terminal Not Needed
The Rating Risks with OWASP Risk Rating Methodology exercise is conceptual — no terminal commands are required. Use the OWASP online calculator and reference material instead.
Common Questions
| Question | Answer |
|---|---|
| Is DREAD still used in industry? | DREAD is largely legacy. OWASP Risk Rating Methodology and FAIR are preferred today. DREAD is taught for historical context. |
| Do I need exact scores for the exercise? | No. The exercise focuses on understanding the scoring process and risk banding, not achieving a specific number. |
| What if my scores differ from the example? | That's fine. Risk scoring is subjective. The discussion and reasoning matter more than the exact values. |
| StrideGPT gives different results each time. | Expected. LLM output is non-deterministic. Focus on the categories of threats identified, not exact scores. |
| The StrideGPT app shows 502 Bad Gateway. | Check .streamlit/config.toml has server.address = "0.0.0.0". Ensure the venv is activated. |
| pip install fails with Distutils Error. | Your venv isn't active. Run source .venv/bin/activate and retry. |
Wrap-Up
Risk rating turns identified threats into actionable priorities. Key takeaways:
- DREAD is a simple 5-dimension model (Damage, Reproducibility, Exploitability, Affected Users, Discoverability). Legacy but useful for learning.
- OWASP Risk Rating is more detailed: 8 factors for likelihood, technical + business impact, averaged to get a risk score banded as Low/Medium/High.
- Not all risks need fixing. Cost-benefit analysis and business context determine treatment.
- StrideGPT automates STRIDE threat identification and DREAD scoring using a local LLM.
- The OWASP Risk Rating exercise is conceptual — no terminal commands needed.
For the StrideGPT lab, remember: devsecops-box-gpu machine, activate the venv, start Ollama, and expect non-deterministic LLM output.