• Cite Icon27
  • https://doi.org/10.1145/2808128.2808129Copy DOI Icon

Blacklist Ecosystem Analysis

  • Oct 12, 2015
  • Leigh Metcalf +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Motivation: We compare the contents of 86 Internet blacklists to provide a view of the whole ecosystem of blocking network touch points and blacklists. We aim to formalize and evaluate practitioner tacit knowledge of the fatigue of playing whack-a-mole against resilient adversary resources. Method: Lists are compared to lists of the same data type (domain name or IP address). Different phases of the study use different comparisons. Comparisons include how many lists an indicator is unique to; list sizes; expanded list characterization and intersection; pairwise intersections of all lists; and following, a statistical test we define to determine if one list adds elements shortly after another. Results: Based on a synthesis of multiple methods, domain-name-based indicators are unique to one list 96.16% to 97.37% of the time. IP-address-based indicators are unique to one list 82.46% to 95.24% of the time. Discussion: There is little overlap between blacklists. Though there are exceptions, the intersection between lists remains low even after expanding each list to a larger neighborhood of related indicators. Few lists consistently provide content before other lists if there is intersection. These results suggest that each blacklist describes a distinct sort of malicious activity and that even merging all lists there is no global ground truth to acquire. Practical insights include (1) network defenders are advised to obtain and evaluate as many lists as practical, (2) whack-a-mole is inevitable due to list dynamics, barring a strategic change, an (3) academics comparing their results to one or a few blacklists to test accuracy are advised to reconsider this validation technique.

Similar Papers
  • Front Matter
  • Citations5

Some Thoughts About Data Type, Distribution, and Statistical Significance

  • Nov 01, 2006
  • The Journal of Foot and Ankle Surgery
  • D Scot Malay
  • Research Article
  • Citations13

Visualizing and characterizing DNS lookup behaviors via log-mining

  • May 16, 2015
  • Neurocomputing
  • Qingnan Lai +4
  • Conference Article
  • Citations34

Analyzing Traffic by Domain Name in the Data Plane

  • Oct 11, 2021
  • Jason Kim +2
  • Conference Article
  • Citations33

Neural reputation models learned from passive DNS data

  • Dec 01, 2017
  • Pierre Lison +1
  • Conference Article
  • Citations5

PicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT Devices

  • Jun 01, 2022
  • Arman Pashamokhtari +3
  • Book Chapter

CHAPTER 8 - Installing, Configuring as a Server

  • Jan 01, 2010
  • Eleventh Hour Linux+
  • Graham Speake
  • Book Chapter

34 - Sending Data to a Server

  • Jan 01, 2004
  • Interactive QuickTime
  • Matthew Peterson
  • Research Article
  • Citations30

Unsupervised, low latency anomaly detection of algorithmically generated domain names by generative probabilistic modeling

  • Jan 09, 2014
  • Journal of Advanced Research
  • Jayaram Raghuram +2
  • Research Article
  • Citations74

ILNP: mobility, multi-homing, localised addressing and security through naming

  • Oct 20, 2009
  • Telecommunication Systems
  • Randall Atkinson +2
  • Research Article

Research on the algorithm for identifying VoIP session

  • Sep 01, 2008
  • Journal of Electronics (China)
  • Shumei Chen +2
  • Conference Article
  • Citations20

A Survey on DNS Security Issues and Mitigation Techniques

  • May 01, 2019
  • Anju Ramdas +1
  • Conference Article

Evaluating Web Protocol Threats: DNS Spoofing & TLS Weaknesses

  • Oct 13, 2025
  • Hamed Nazariyan +2
  • Book Chapter
  • Citations10

AmritaDGA: a comprehensive data set for domain generation algorithms (DGAs) based domain name detection systems and application of deep learning

  • Jul 04, 2019
  • R Vinayakumar +4
  • Research Article
  • Citations48

Extending Black Domain Name List by Using Co-occurrence Relation between DNS Queries

  • Jan 01, 2012
  • IEICE Transactions on Communications
  • Kazumichi Sato +4
  • Book Chapter
  • Citations2

Blockchain-Based Sealed-Bid Domain Name Auction Protocol

  • Jan 01, 2021
  • Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
  • Genhua Lu +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.