The invention relates to a detection and
processing method and a
system for
botnet domain names. The detection and
processing system is composed of an input module, an output module, a real-time calibration module and a
processing module. The method comprises the step: 1) carrying out log query on a to-be-detected
network domain name, and obtaining a log
record of
domain name query and inputting the log
record to a detection port; 2) extracting and obtaining characteristics of the
domain name according to the log
record of the
domain name query, and carrying out
machine learning on the characteristics of the domain name; 3) after the
machine learning, extracting the
botnet domain names in
a domain name on an outgoing line and / or a
local domain name log; and 4) building a data base of the
botnet domain names, carrying out breakdown through a
black hole authoritative
server, and finishing the processing. According to the detection and processing method and the
system for the botnet domain names, while the botnet domain names can be extracted from
a domain name server (DNS) to be broken down and separated so as to crack down botnet crimes, the botnet domain names are collected, and a network bad action that a botnet host is connected with a controlling end through the domain names so as to receive vicious commands is effectively prevented.