Skip to content

A comprehensive method for identifying and prioritizing information security threats based on the integration of the MITRE ATT&CK and DREAD frameworks and the methodology of the FSTEC of Russia

2026 · SOFT MEASUREMENTS AND COMPUTING · Vol 6/4, pp. 144-155 · 0 citations

TL;DR

The authors propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks, including the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model.

Abstract

The authors analyze the limitations of existing approaches when applied in isolation, noting the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model. As a solution, they propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks. The developed approach includes an algorithm for mapping threats from the FSTEC database to MITRE ATT&CK attack techniques and uses adapted DREAD metrics to rank risks based on existing protective measures. The practical significance of the study lies in the presentation of a step-by-step implementation algorithm, including asset inventory, security audit, and security budget optimization, making the tool applicable to organizations of all sizes.

View source

Similar papers

2026

A method for assessing the information security level of banking sector organizations based on an analysis of the implementation of protection measures

A methodology is proposed for assessing the information security level of an automated banking system by linking relevant information security threats, the implementation status of organizational and technical security measures, and an integrated regulatory assessment. Relevant threats are identified using the Threat D...

Maksim A. Manin, Eva V. Prediger · 0 citations
2026

Integration of Vulnerability Databases into ISMS: A Path to Enhancing Cyber Resilience of Critical Systems

A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cy...

V. Yashchuk, A. Ivanusa, N. Maslova et al. · 1 citation
Review Open access Aug 2026

Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems

A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.

Mohammed AbuTaha · 0 citations
Aug 2026

Methodology of information security audit of critical information infrastructure subjects: synthesis of reference modeling and quality assessment

This article examines the discrepancy between the growing volume of regulatory requirements for protecting the Russian Federation’s critical information infrastructure and the lack of objective methods for quantitatively assessing their implementation. A comparative analysis of domestic regulations and international st...

Nikita A. Nilov, A. V. Dushkin, Evgeny M. Portnov et al. · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Aug 2026

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and kn...

Serge Benoliel, Florence Foudrain · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.