Download PDFOpen PDF in browserKeep It Lean: Longitudinal Maintenance of URL Blocklists Using Real-User Web Access Logs13 pages•Published: August 6, 2026AbstractThe rapid proliferation of malicious websites poses a significant threat to Internet users. While URL-based blocklists are widely used as a practical defense mechanism, their effectiveness depends not only on identifying newly emerging malicious URLs but also on maintaining the blocklist appropriately over time. This study evaluates the long-term operational effectiveness of a URL blocklist generated from real-user Web access logs.From June 2024 to January 2026, we operated a URL blocklist generation method proposed in our previous work. We collected web access logs from real users and identified malicious URLs related to actual browsing activities. By adding these URLs and removing entries not accessed for more than two weeks, we maintained our blocklist every day and conducted a longitudinal cross-referencing experiment. Over 337 days, 6,866 malicious URLs were identified while maintaining an average blocklist size of 1,248 URLs. The blocklist matched 2,817 accesses from 102 users. We also found that 17% of the malicious URLs were removed soon after, whereas some URLs remained active for long periods. In addition, accesses to URLs after removal revealed limitations of simple lifetime-based maintenance. Finally, we conducted a real-user deployment in which the blocklist was updated daily and distributed weekly. Over 569 days, 13,208 malicious URLs were identified, while the average blocklist size was maintained at 1,330 URLs. During the 20-month evaluation, 84 users accessed URLs included in the blocklist 844 times. These results demonstrate that continuous removal of URLs can provide practical protection in real browsing environments while maintaining a relatively small blocklist size. Keyphrases: longitudinal analysis, url blocklist maintenance, web access log In: Tung-Tso Tsai, Huy Kang Kim, Yujue Wang and Akira Yamada (editors). Proceedings of The 21st Asia Joint Conference on Information Security, vol 111, pages 66-78.
|

