http://www.securiteam.com/securityrevie ... 1P5PY.html
And this more recent paper which covers fast flux dns.. a method of hiding the source.. modern botnets are implementing this, making it even harder to track.
http://www.honeynet.org/papers/ff/fast-flux.html
I am fascinated by this type of stuff... When I was reading the first paper my reaction was "i want to build one!" but it's a good thing I'm a lazy p.o.s! It just seems like such fun to play around with, if you're not too evil about it..
