short Botnet list and Cashing in on DoS

so, i'd written:

> 2. Filter aggressively. Run a dark-net, and if one of your customers...

my nameless friend then asked me:

this sounds intrigueing, but I'm not sure what it is. Is is sort of an
internal honeypot NETWORK?

it goes by several names. network telescope, darknet, etc. i called it
a darknet above only because rob thomas calls it that, and he'd recently
given a talk at the dns-oarc members meeting on this precise topic.
yes, it's like a honeypot in some ways (but robt probably winced just
now, as he read me saying that.) most of rob's talk is echoed by his web
site <;, which is a good read.

my own "darknet"-like project is wired up to a database that can answer
questions like "what are the worst 25 sources of undesireable smtp since
the last time i reset the database?" today's answer is:

smtpk=> select * from top25_bysrc;
       src | howmany | earliest | latest