IP Blocklists - Blocking Known Malicious Sources
About 2 min read
An IP blocklist is a list that registers IP addresses confirmed to be engaged in malicious activity and automatically denies access from them. By incorporating it into the rules of a firewall or a WAF, you can block communication from known attack sources right at the entrance. As of 2025, operations that update blocklists in real time through automatic integration with threat intelligence feeds have become common.
Two Ways to Use a Blocklist: Reactive and Preventive Blocking
There are two directions in which a blocklist can be used. One is reacting to an attack that is actually underway. By identifying the sources from the attacking traffic and adding them to the blocklist, subsequent attack traffic is refused at the entrance, reducing the load on the server. When an attacker rotates through neighboring addresses one after another, an entire address range can be registered instead of a single IP, though the wider the block, the greater the risk of catching legitimate users as well. The other is prevention against parties that have not yet made contact. By registering in advance addresses already reported as malicious by threat intelligence feeds and similar sources, the very first contact can be refused. Reactive blocking rests on your own observations, while preventive blocking rests on the observations of others; combining the two narrows the gaps in your defenses.
Types of Blocklists
Public blocklists (such as Spamhaus and AbuseIPDB) are services that share the IP addresses of spam senders and malware distributors across the community. Commercial threat intelligence feeds provide more accurate IP reputation information. An in-house blocklist is one in which you register, on your own, the attack-source IPs detected through your own log analysis; operating it with automatic updates linked to a SIEM is effective.
| Type | What gets registered | How it is updated | Typical use |
|---|---|---|---|
| Public blocklists (Spamhaus, AbuseIPDB, and others) | IP addresses of spam senders and malware distributors | You reference a list shared across the community | Checked as a DNSBL on mail servers to refuse reception |
| Commercial threat intelligence feeds | More accurate IP reputation information | Updated in real time through automatic integration (common practice as of 2025) | Preventively blocking the IPs of related C2 servers |
| In-house blocklist | Attack-source IPs detected through your own log analysis | Automatically updated in tandem with a SIEM | Adding an attack source range (/24) to the WAF IP set during a DDoS attack |
Operational Scenarios
When a DDoS attack on a web server is detected, you add the attack source's IP address range to the blocklist and cut it off immediately. On mail servers, the IPs of spam senders are checked against a DNS-based blocklist (DNSBL), and reception is refused. In cloud environments, by combining the AWS WAF IP set with CloudFront geo-restriction, access control on a per-country basis is also possible. By using DNS security together with an IP blocklist, you can achieve a multi-layered defense.
Operational Considerations
The biggest challenge with IP blocklists is false positives. If you block a shared IP address (a NAT environment, a CDN, or a VPN), legitimate users get caught up in it as well. You need to review the blocklist periodically and operate it so that unnecessary entries are removed. In addition, because attackers frequently change their IP addresses, do not rely on the blocklist alone; combine it with rate limiting and behavioral analysis. It is also important to protect the firewall's management console with a strong random password.
Was this article helpful?