← Latest papers
💻 computer science

Instrument Effects in the Measured Lifetime of Malicious Domains: A Two-Instrument Decomposition by Cause

This paper analyzes 122,458 malicious domains to demonstrate that measured lifetimes are significantly distorted by the observing source, revealing that feed-based estimates overcount deaths by 55.06% compared to registration records primarily due to unobservable operator abandonment, thereby necessitating a two-instrument decomposition to accurately attribute domain exit causes.

Original authors: Düzgün Küçük, Fatih Ertam

Published 2026-09-24
📖 5 min read🧠 Deep dive

Original authors: Düzgün Küçük, Fatih Ertam

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital world, bad actors constantly register thousands of web addresses to spread malware or steal information. Security teams rely on threat intelligence feeds—essentially constantly updated lists of these dangerous addresses—to protect their networks. A critical decision for these teams is how long to keep an address on their watchlist. If they remove a dangerous address too soon, they leave a door open for attackers. If they keep it on the list too long after it is no longer a threat, they waste valuable resources and create unnecessary noise. To make this decision, teams need to know how long a malicious website typically survives before it is shut down or abandoned. However, measuring this "lifespan" is surprisingly difficult because the tools used to track these websites often see a different reality than the actual registration records of the domain names.

A new study by researchers Düzgün Küçük and Fatih Ertam investigates exactly how these tracking tools distort our understanding of how long malicious websites live. The researchers gathered a massive collection of over 122,000 malicious domain names that appeared on a threat feed between 2018 and 2026. Instead of just trusting the feed's list, they cross-referenced every single one of these domains with independent records, such as official registration databases and passive DNS data, which track how domain names are actually used on the internet. By comparing what the threat feed said about a domain's life and death against what the independent records showed, the team could separate the true life of the website from the artificial limits of the list itself.

The study reveals that the way a threat feed reports a domain's death is often misleading. When a domain disappears from a threat feed, it is usually counted as "dead." However, the researchers found that in many cases, the domain was still active and resolving on the internet; it had simply been dropped from the list because the feed's operators decided it was no longer a priority or had stopped monitoring it. This creates a "surveillance bias," where the act of watching a subject changes the measurement of its life. The researchers identified three distinct reasons why a malicious domain stops being a threat: it is forcibly taken down by authorities, its registration is cancelled by the owner, or the operator simply abandons it. The independent records could only see the first two causes. The third cause, abandonment, was invisible to the records because the domain name remained registered even though the bad actor walked away.

When the researchers compared the two sources of information, the difference was stark. The independent records showed that about 35 percent of the domains had truly died. The threat feed, however, reported that 55 percent were dead. This 20 percentage point gap was not a measurement error but a fundamental difference in what the two tools could see. The researchers calculated that nearly three-quarters of this discrepancy came from the "abandonment" cause. Because the threat feed stops watching a domain once the operator abandons it, the feed counts that moment as a death, while the registration records show the domain is still technically alive and registered. This means that for the specific cause of abandonment, the feed is measuring its own policy of when to stop looking, not the actual lifespan of the malicious infrastructure.

The study also looked at how long it takes for a malicious domain to appear on a threat feed after it is first created. The researchers found that this delay is often extremely long, with some domains taking years to be added to the list. This suggests that the "clock" for measuring a domain's life should start when it is listed on the feed, not when it was originally created, because the delay is part of the threat intelligence process itself. Furthermore, the team tested whether current rules for removing old indicators from watchlists were effective. They found that if a team uses a rule based on the feed's timeline without accounting for the delay in listing, they might remove indicators that are still active. Specifically, on a subset of domains where the exact end date was known, a standard rule would have removed about 6 percent of domains that were still alive and dangerous.

Ultimately, the research concludes that security teams cannot simply copy retention policies from one source to another. A rule that works for a threat feed will not work for a system based on registration records, because the feed includes a specific type of "death" (abandonment) that the records cannot see. The study provides a clear method for separating the true lifespan of a malicious domain from the artificial limits of the tools used to track it. By understanding that a significant portion of what looks like a domain dying is actually just the observer stopping the watch, security teams can adjust their strategies to keep dangerous addresses on their lists for the right amount of time, ensuring they do not let a threat slip away too early or waste effort on one that has already vanished.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →