hi netfilter folks!

i would like to reduce the amount of damage that scanning worms such 
as slammer can do by limiting the number of destination ips per 
second that a host in my network can connect to.
ideally, the host would be blackholed after repeatedly hitting this 
limit, and a LOG message would trigger an alert to the admin.

the way i understand the _limit_ match, it can only be used to 
reduce throughput to or from particular address, but does not have 
enough state information that would allow to correlate different 
connections from the same host.

now i have googled up, 
which mentions the _dstlimit_ match, but i'm not sure how it works. 
i found the source file in netfilter cvs, but did not really 
understand it. might it be what i'm looking for?

if this has been discussed before, please point me to the relevant 
threads - i searched far and wide, but nothing.

