O.K.
since the newbies want to be serious
( what happened to the unix sense of humor? )
Oh, wait, I'm a newbie!

What if I took Iptables,
took all the rejected packets and sent them into "user space"
then wrote a script to append the table rules to take the IP address of those rejected packets and mirror them.

Oh, and released it under the GNU license.

Would this be like what they were talking about??

Do you think that would bog things down a bit??

How do you think the ISP's would react??