A few highly publicized incidents have demonstrated the threat posed by denial-of-service attacks, but the community has no current, quantitative data about how serious a problem this actually is. Moreover, collecting such information is complicated by the distributed nature of attacks and concerns about privacy.
To this end, we have implemented a new technique, called "backscatter analysis," that allows us to observe worldwide denial-of-service activity without requiring widespread cooperation. Over the course of several weeks we observe several thousand DoS attacks, measure their behavior, duration, topological and geography locality, and characterize what types of sites are victimized most often.
A paper describing the technique is available HERE.