DGA embedded in the malware generate a large amount of pseudo-random domain names within a given period, most of which are nonexistent. The sheer amount of nonexistent domains produced by the DGA on a daily basis presents a great burden for security specialists if blocklisting is still to be pursued. New DGA detection methods have been proposed[1] which analyze the statistical and linguistic features of the domain names and the related network traffic to determine whether they are generated algorithmically. The output of our component is a randomness score on which decision can be made as to whether the input is an algorithmically generated domain name.”]
Source: https://blog.talosintelligence.com/2015/08/research-spotlight-detecting.html