Recently, a lot of information security accidents such as APT(Advanced Persistent Threat), Ransomware,
Drive-By-Download, and distribution of malicious code through e-mail have occurred in various public
institutions and financial institutions. Such malicious attacks are becoming more intelligent, and the number is also increasing. In particular, the majority of public institution security monitoring centers establish
blocking policies for such malicious IPs for a certain period of time. However, the existing reuse of
malicious IP has been increasing, and the reoccurrence of information security accidents is also increasing.
In this paper, the harmful IP storage cycle is calculated through the harmful IP detection, the elapsed days,
the occurrence ratio and the reuse ratio for the harmful IP. As a result of analyzing the statistical
characteristics of legacy data, it is desirable to keep the harmful IP for one year without any domestic or
foreign distinction. However, when the elapsed days are listed in order of magnitude 95% of the value is
calculated to provide the recommended method to manage the minimum storage period of harmful IP.