The present disclosure provides a malicious
domain name processing method, device, device and
machine-readable storage medium. The method includes: acquiring training samples that meet preset requirements, extracting sample features from the training samples according to preset dimensions; and according to the extracted sample features , perform sample clustering on the training samples, and use BiLstm to
train and generate a classifier; use the classifier to process the features extracted according to the
domain name to be determined, and determine whether the
domain name to be determined belongs to the DGA domain name; the preset dimensions include :
Domain name length, initial proportion, numerical proportion, domain name entropy. Through the technical solution of the present disclosure, the initials of
pinyin are used as one of the dimensions of the training model, and the
algorithm model obtained can effectively reduce the
false alarm rate of domestic websites. At the same time, the training method provided by the present disclosure has simple and efficient
feature extraction, and can determine the DGA domain name. High accuracy and
low resource consumption.