BlockMeNot: Automatic Selection of Domain and URL Blocking Granularity to Minimize Collateral Damage and Evasion
Daud Ahmed, Srdjan Matic, Platon Kotzias, Emiliano Carlesi, Juan Caballero
摘要
Domain and URL blocking is a fundamental mechanism for mitigating malicious, illegal, and inappropriate online content. Yet, selecting the right blocking granularity remains a largely unexplored problem. Overblocking can cause severe collateral damage if the content to be blocked uses the infrastructure of benign services, which may be unintentionally disrupted. Underblocking instead enables trivial evasion. This paper addresses this gap by proposing a novel approach that, given a domain or URL to be blocked, automatically selects the most appropriate blocking granularity (URL, subdomain, or apex) to minimize collateral damage and evasion opportunities. At the core of our approach are two novel machine learning classifiers to identify URL-leasing and subdomain-leasing apexes. The classifiers are trained and evaluated using a manually labeled dataset of 10,843 apexes, achieving F1 scores over 0.9. We implement our approach into BlockMeNot, a tool for identifying potential collateral damage prior to enforcement. We evaluate BlockMeNot on 225,355 entries (i.e., domains and URLs) collected from six blocklists and two threat exchanges. Although only 2.6% of apexes belong to leasers, they host 34.7% of the entries, and up to 71.7% in phishing-focused blocklists, underscoring the importance of fine-grained blocking. BlockMeNot identifies 1,976 leasing apexes, 59.3% of which were not in our ground truth, demonstrating the limitations of static lists and the need for our classifiers. Only 37.2% of blocklist entries are listed at the optimal granularity, 1.3% produce collateral damage, and 61.6% enable easy evasion. Overall, our work provides the first automated solution for domain and URL blocking granularity selection and offers practical guidance for block requesters, executors, and blocklist maintainers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn 等S&P 2019 · 被引用 129 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang 等CCS 2017 · 被引用 60 次
- Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLsRavindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil 等USENIX Security 2021 · 被引用 45 次
相关 Paper
- Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksSumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang 等S&P 2017 · 被引用 51 次
- MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting InfrastructureFatih Deniz, Mohamed Nabeel, Ting Yu, Issa KhalilS&P 2025
- Catching Transparent Phish: Analyzing and Detecting MITM Phishing ToolkitsBrian Kondracki, Babak Amin Azad, Oleksii Starov, Nick NikiforakisCCS 2021 · 被引用 37 次
- Phishing URL Detection: A Network-based Approach Robust to EvasionTaeri Kim, Noseong Park, Jiwon Hong, Sang-Wook KimCCS 2022 · 被引用 21 次
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 被引用 3 次
