skip to content

DREAD Scoring

DREAD averages damage, reproducibility, exploitability, affected users and discoverability into one figure, and the inputs drift between raters. Interviewers ask why it fell out of favour.

on this pageshow

questions

4

What do the five letters in DREAD stand for, and how is a DREAD score produced?

level: juniorimportance: must knowfreq 48%

answer

  1. five ordinal ratings, one number
  2. starts with how bad the outcome is
  3. two of the five are impact dimensions
  4. the last one is about being found
  5. combine the five by averaging

basics

~20 s

DREAD rates a threat on five dimensions - Damage, Reproducibility, Exploitability, Affected users and Discoverability - each given a small ordinal rating in the room, then collapses them into one number, classically their arithmetic mean.

solid answer

~50 s

DREAD is a per-threat rating scheme with five dimensions: **Damage** (how bad the outcome is if it happens), **Reproducibility** (how reliably the attack works when repeated), **Exploitability** (how much skill, access or effort it takes to pull off), **Affected users** (how much of the population is hit) and **Discoverability** (how easily an attacker finds the flaw in the first place). Each dimension gets an ordinal rating from a small scale - the classic form is 1 to 10, a common lighter variant is 1 to 3 - and the classic aggregation is the arithmetic mean of the five, giving one number you sort the threat list by. Two of the dimensions (Damage, Affected users) are about impact; the other three are about how likely and how easy the attack is. Nothing in DREAD comes with externally published per-value criteria, so the digits are the room's judgment, not a measurement.

go deeper

for a junior

Be ready to expand all five letters cleanly and say that the classic score is the average of five ratings. Do not confuse Reproducibility of the attack with reproducibility of the scoring.

for a middle

Explain that two dimensions measure impact and three measure ease or likelihood, and that the ratings are ordinal judgments with no externally published criteria behind them.

for a senior

Show where the scheme fits in a real session: enumeration produces the list, DREAD only orders it, and the ninety seconds it takes per threat is the main thing it has going for it.

for a principal

An interviewer expects you to frame it as one instrument among several and to be clear about what an unanchored per-threat number can and cannot justify to a stakeholder.

## What DREAD is for Once you have enumerated threats against a design, you have a list that is too long for the sprint you actually have. Risk rating is the step that turns that list into an order. DREAD is one of the oldest and simplest instruments for doing that: it asks five questions about each threat, takes a small ordinal rating for each, and combines them into a single number you can sort by. It came out of Microsoft in the early 2000s and was commonly taught alongside STRIDE - STRIDE to find the threats, DREAD to rank them - and it was later dropped from that guidance, for reasons this leaf's other questions cover. ## The five dimensions - **D - Damage potential.** How bad is the outcome if this threat is realised? Total loss of the data, a single record leaked, a few minutes of degraded service. This is an impact dimension. - **R - Reproducibility.** How reliably does the attack work if the attacker tries it again? A deterministic request that works every time rates high; a race that needs precise timing and succeeds one attempt in fifty rates low. Note the trap: this is about the *attack* being repeatable, not about your *scores* being repeatable, which is a completely different property and the one DREAD is most criticised for lacking. - **E - Exploitability.** How much effort, skill, tooling or pre-existing access does the attacker need? An unauthenticated request from anywhere rates high; something that needs a foothold on the host plus reverse-engineering rates low. - **A - Affected users.** How much of the population is hit? One administrator, one tenant, or everybody. This is the second impact dimension, and it is the blast-radius question. - **D - Discoverability.** How easily does an attacker find the flaw at all? Visible in a URL parameter rates high; buried in an undocumented internal message format rates low. A useful way to hold them: two dimensions ask *how bad*, three ask *how likely and how easy*. ## Producing the number Each dimension gets a rating from a fixed small scale. The original form uses 1 to 10 per dimension and takes the arithmetic mean of the five, so a threat's DREAD score also lands between 1 and 10. A widely used lighter variant scores each dimension 1, 2 or 3 (low / medium / high) and reads the *sum* against bands rather than averaging. Either way, the output is one number per threat, and the working assumption is that sorting by that number gives you a defensible order of work. A worked example on a multi-tenant reporting service, where the attacker position is an ordinary authenticated tenant with a valid login. The threat is that changing an identifier in a request returns another tenant's report: | Dimension | Rating | Why | | --- | --- | --- | | Damage potential | 7 | another customer's business data is exposed | | Reproducibility | 10 | the same request works every time | | Exploitability | 9 | edit one number in a URL, no tooling needed | | Affected users | 8 | every tenant on the shared instance | | Discoverability | 8 | the identifier is visible in the address bar | Mean of the five: **8.4**. That 8.4 is a DREAD score. It took about ninety seconds to produce, which is genuinely the scheme's strength. ## What the number is and is not It is worth being precise about the vocabulary, because interviewers probe it. The *threat* is "a tenant reads another tenant's report". The *vulnerability* is the missing ownership check on the identifier. The *risk* is the rated consequence - which is what DREAD is trying to express. The *control* is the ownership check you add. DREAD rates the third of those; it does not find threats, and it does not tell you what to build. It is also not a standard in the sense that a published scoring specification is. There is no authoritative document that tells you what Damage 7 means as opposed to Damage 6, so two teams rating the same threat are not using the same instrument even though they are using the same acronym. Some teams write their own per-value criteria to fix exactly this, and that is a reasonable thing to do - but the scheme does not ship with them. ## Where it sits in an interview Recalling the five letters is a screening-level question and you should be able to expand them without hesitation, including which two are impact dimensions. The follow-up is almost always about the arithmetic - whether averaging five subjective ordinal guesses gives you a number worth sorting by - so do not present the mean as though it were a measurement.

  • Which DREAD dimensions describe impact, and which describe likelihood?
    Damage potential and Affected users describe impact - how bad the outcome is and how many people it reaches. Reproducibility, Exploitability and Discoverability describe how likely and how easy the attack is. Averaging all five into one number therefore blends two axes that most risk methods deliberately keep separate, which is one reason the composite is hard to interpret.
  • What scale do the dimensions use, and does the scale change what the score means?
    The classic form scores each dimension 1 to 10 and averages; a lighter variant scores each 1 to 3 and reads the sum against bands. The scale changes the granularity but not the underlying property: in both cases the ratings are ordinal judgments, so a 10 is not ten times a 1, and the arithmetic treats the gaps as if they were equal.
  • Where does DREAD sit relative to threat enumeration?
    It runs after enumeration. Something else - a structured category walk over the design, an attack tree, an abuse case - produces the list of threats; DREAD only rates threats that already exist on the list. It has no elicitation power of its own, so a team that uses DREAD alone will rank a short and probably incomplete list very confidently.

It is a five-question opinion poll about one threat, where the answers are averaged into a single grade - fast to run, and only as good as the people answering.

saying these in an interview costs you the question

  • Calling DREAD a threat-enumeration method rather than a rating scheme
  • Reading the R as reproducibility of the score instead of the attack
  • Presenting the averaged digit as a measurement rather than a judgment
  • Cannot say which two dimensions are about impact
  • Claiming DREAD has published per-value criteria for each rating

context

open as a page

Why is DREAD's Discoverability dimension criticised as security by obscurity?

level: middleimportance: should knowfreq 33%

basics

~10 s

Discoverability lowers a threat's score because the flaw is hard to find, crediting obscurity as if it were a control. The vulnerability is unchanged; only attacker knowledge is, and that can shift overnight.

open as a page

Two threats both average 6 in DREAD, one of them scoring Damage 1 and Affected users 10 - why is that ranking untrustworthy?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Averaging five ordinal guesses destroys a threat's shape: a trivial issue touching everyone lands on the same digit as a moderate-everywhere one. The ratings are also unanchored, so a later session produces different digits from identical facts.

open as a page

Is DREAD worth keeping for a thirty-minute threat model of an internal service?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Keep the five prompts, throw away the arithmetic. Asking about damage, repeatability, effort, blast radius and visibility structures a short discussion well; computing and publishing a mean gives a number nobody can reconstruct or defend later.

open as a page