Skip to content

A comprehensive method for identifying and prioritizing information security threats based on the integration of the MITRE ATT&CK and DREAD frameworks and the methodology of the FSTEC of Russia

2026 · SOFT MEASUREMENTS AND COMPUTING · 0 citations

Abstract

The authors analyze the limitations of existing approaches when applied in isolation, noting the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model. As a solution, they propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks. The developed approach includes an algorithm for mapping threats from the FSTEC database to MITRE ATT&CK attack techniques and uses adapted DREAD metrics to rank risks based on existing protective measures. The practical significance of the study lies in the presentation of a step-by-step implementation algorithm, including asset inventory, security audit, and security budget optimization, making the tool applicable to organizations of all sizes.

View source