Tl;dr: correlation of great many DNS queries allows to discover malware c&c networks, and block them. Works without prior knowledge, using just stats / ML.
Fascinating. They don't mention but I can't help but wonder if time and source also are fed into the correlation net.