Skip to content

A comprehensive method for identifying and prioritizing information security threats based on the integration of the MITRE ATT&CK and DREAD frameworks and the methodology of the FSTEC of Russia

2026 · SOFT MEASUREMENTS AND COMPUTING · Vol 6/4, pp. 144-155 · 0 citations

TL;DR

The authors propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks, including the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model.

Abstract

The authors analyze the limitations of existing approaches when applied in isolation, noting the insufficient specification of the FSTEC methodology, the lack of prioritization mechanisms in the MITRE ATT&CK knowledge base, and the subjectivity of the quantitative assessments of the DREAD model. As a solution, they propose a comprehensive methodology based on the mathematical formalization of the integration of these three frameworks. The developed approach includes an algorithm for mapping threats from the FSTEC database to MITRE ATT&CK attack techniques and uses adapted DREAD metrics to rank risks based on existing protective measures. The practical significance of the study lies in the presentation of a step-by-step implementation algorithm, including asset inventory, security audit, and security budget optimization, making the tool applicable to organizations of all sizes.

View source

Similar papers

2026

A method for assessing the information security level of banking sector organizations based on an analysis of the implementation of protection measures

A methodology is proposed for assessing the information security level of an automated banking system by linking relevant information security threats, the implementation status of organizational and technical security measures, and an integrated regulatory assessment. Relevant threats are identified using the Threat Database maintained by the Federal Service for Technical and Export Control of Russia (FSTEC of Russia). For each threat, a set of required security measures is defined, and the degree of their implementation is assessed according to the criteria of GOST R 57580.2-2018, which take into account the planning, implementation, monitoring, and improvement of information security processes. The resulting assessments of security measures are aggregated into group-level and integrated indicators in accordance with the framework of STO BR IBBS-1.2-2014. The practical significance of the study lies in improving assessment transparency, automating analytical procedures, reducing the workload of information security specialists, and providing a basis for repeated monitoring of the security posture. The methodology is intended to assess the current information security level of the automated banking system under study within the selected scope and does not replace formal procedures for assessing compliance with regulatory requirements.

Maksim A. Manin, Eva V. Prediger · 0 citations
2026

Integration of Vulnerability Databases into ISMS: A Path to Enhancing Cyber Resilience of Critical Systems

A conceptual model and methodological framework are proposed for embedding data from vulnerability databases into ISMS processes in alignment with ISO/IEC 27001/27002 and NIST recommendations, and provides methodological and architectural foundations for implementing integrated vulnerability management and enhancing cyber resilience in critical infrastructure environments.

V. Yashchuk, A. Ivanusa, N. Maslova et al. · 1 citation
Review Open access Aug 2026

Enhancing Government Cybersecurity through the Utilization of Automated and AI-Driven Techniques to Fortify Security Information and Event Management (SIEM) Systems

A better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up is suggested.

Mohammed AbuTaha · 0 citations
Aug 2026

Methodology of information security audit of critical information infrastructure subjects: synthesis of reference modeling and quality assessment

This article examines the discrepancy between the growing volume of regulatory requirements for protecting the Russian Federation’s critical information infrastructure and the lack of objective methods for quantitatively assessing their implementation. A comparative analysis of domestic regulations and international standards reveals a fundamental methodological discrepancy at the metric level: Russian regulations rely on qualitative, binary assessments, while global practice is shifting toward quantitative measurement of process efficiency and maturity. A two-tier qualimetric assessment model is proposed that synthesizes mandatory regulatory requirements with CMMI principles. The model includes the calculation of a basic «hygienic minimum» performance indicator and an integrated maturity assessment across five domains (identification, protection, detection, response, and recovery) based on an ordinal scale and weighting factors. Implementation of the proposed approach helps overcome this discrepancy, objectify audit results, and create incentives for the continuous improvement of critical information infrastructure protection systems in the face of escalating cyber threats.

Nikita A. Nilov, A.V. Dushkin, Evgeny M. Portnov et al. · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

This study evaluates the comparative effectiveness of two widely adopted cybersecurity frameworks, the OWASP Top Ten (2021) and the OWASP Web Security Testing Guide (WSTG), in the context of web application security auditing. While the OWASP Top Ten is a standard for risk awareness, it lacks the technical granularity required for comprehensive testing, creating a gap between high-level risk identification and practical verification. To bridge this gap, this study proposes a structured integration through comparative mapping and empirical validation using real-world mitigation data. A procedural analysis combined with granularity evaluation was employed to map the ten OWASP risk categories to 102 technical verification units in the WSTG. The results reveal a 920% increase in testing granularity compared to the baseline Top Ten framework. Empirical validation conducted on a government subdomain (Instansi X) demonstrated that this integrated approach identified critical vulnerabilities, including Broken Access Control and Cryptographic Failures, which are often overlooked in high-level assessments. By implementing specific WSTG-based mitigation procedures, such as middleware authorization and secure communication protocols, identified risks were successfully remediated without disrupting production stability. This study contributes a validated framework that bridges the gap between conceptual risk and actionable technical verification. The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework. This integration enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Aug 2026

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios.

Serge Benoliel, Florence Foudrain · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.