Download PDFOpen PDF in browserA Longitudinal Validation of Cluster-Based Phishing Analysis: Tracking High-Impact Clusters Targeting Japan17 pages•Published: August 6, 2026AbstractPhishing attacks targeting Japan have caused growing financial damage, motivating cluster-based analysis as a framework for prioritizing defensive actions. However, the longitudinal validity of such clusters — whether their definitions remain effective as phishing activity evolves — has not been empirically evaluated. We address this gap by applying cluster definitions and YARA rules established from 2023 data to 100,594 domains observed in 2024, and by comparing fixed 2023 rules against periodically updated 2024 operational rules. We find that 60.6% of 2024 domains are classified into the same clusters using only the 2023 rules, but trackability is non-uniform: high-impact clusters remain stable through Q1—Q2 and then degrade rapidly at the Q2—Q3 boundary, with the rule stable rate of high impact clusters dropping by an order of magnitude within a single quarter. The gap between fixed and updated rules splits into three operationally distinct components: rule degradation (18.0%), newly emerged clusters (18.3%), and classification conflicts (3.1%) — of which the first two dominate at comparable scale. Characterizing clusters along two axes — stability category (High/Medium/Low) and temporal pattern (Stable/Degrading/Volatile) — we provide quantitative guidance for scheduling rule maintenance.Keyphrases: cluster based analysis, longitudinal validation, phishing, yara In: Tung-Tso Tsai, Huy Kang Kim, Yujue Wang and Akira Yamada (editors). Proceedings of The 21st Asia Joint Conference on Information Security, vol 111, pages 49-65.
|

