USENIX Security2026Top-tier venue
BlockMeNot: Automatic Selection of Domain and URL Blocking Granularity to Minimize Collateral Damage and Evasion
Daud Ahmed, Srdjan Matic, Platon Kotzias, Emiliano Carlesi, Juan Caballero
Abstract
Domain and URL blocking is a fundamental mechanism for mitigating malicious, illegal, and inappropriate online content. Yet, selecting the right blocking granularity remains a largely unexplored problem. Overblocking can cause severe collateral damage if the content to be blocked uses the infrastructure of benign services, which may be unintentionally disrupted. Underblocking instead enables trivial evasion. This paper addresses this gap by proposing a novel approach that, given a domain or URL to be blocked, automatically selects the most appropriate blocking granularity (URL, subdomain, or apex) to minimize collateral damage and evasion opportunities. At the core of our approach are two novel machine learning classifiers to identify URL-leasing and subdomain-leasing apexes. The classifiers are trained and evaluated using a manually labeled dataset of 10,843 apexes, achieving F1 scores over 0.9. We implement our approach into BlockMeNot, a tool for identifying potential collateral damage prior to enforcement. We evaluate BlockMeNot on 225,355 entries (i.e., domains and URLs) collected from six blocklists and two threat exchanges. Although only 2.6% of apexes belong to leasers, they host 34.7% of the entries, and up to 71.7% in phishing-focused blocklists, underscoring the importance of fine-grained blocking. BlockMeNot identifies 1,976 leasing apexes, 59.3% of which were not in our ground truth, demonstrating the limitations of static lists and the need for our classifiers. Only 37.2% of blocklist entries are listed at the optimal granularity, 1.3% produce collateral damage, and 61.6% enable easy evasion. Overall, our work provides the first automated solution for domain and URL blocking granularity selection and offers practical guidance for block requesters, executors, and blocklist maintainers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d9c2556-c2e7-4d14-8c2a-6a07f72d2ba5Builds on14
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin et al.CCS 2016 · 89 citations
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLsRavindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil et al.USENIX Security 2021 · 45 citations
Related papers
- Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksSumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang et al.S&P 2017 · 51 citations
- MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting InfrastructureFatih Deniz, Mohamed Nabeel, Ting Yu, Issa KhalilS&P 2025
- Catching Transparent Phish: Analyzing and Detecting MITM Phishing ToolkitsBrian Kondracki, Babak Amin Azad, Oleksii Starov, Nick NikiforakisCCS 2021 · 37 citations
- Phishing URL Detection: A Network-based Approach Robust to EvasionTaeri Kim, Noseong Park, Jiwon Hong, Sang-Wook KimCCS 2022 · 21 citations
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 3 citations
