Paper on some scary abuse of DNS and other protocols that can be used for command/control of botnets.  Hard to detect these sorts of things.

http://www.shmoocon.org/slides/botnet_v1.0_2.pdf