>There's a lot of this about.

I agree ... and I have some extensive measurements of it

>We did awhile back wonder if it was botnet-related, but I've not (yet)
>seen any persuasive evidence that it is.

I agree with the view that it's an attack on the authoritative server
and I have been told that it's pretty effective at that!

Although the attack could be done with a botnet or by reflecting traffic
off end-user equipment, many of the attacks I have seen involve source
IP spoofing. I deduce this by noting that a fairly large percentage of
the traffic comes from blocks of IPs that are not currently routed on
the open Internet.

I wonder the extent to which the end-user equipment is being blamed when
it's just routed IPs which are being used.

It would be interesting to confirm my observation (or at least segment
the attacks into those where this is a tactic).

