Malware
Sinkhole
Sinkhole is a domain or IP taken over by defenders so that infected machines calling it reach the defender's server instead of the attacker's. The traffic becomes a count of victims.
How it is measured
Set DNS for the domain to a server you operate, or have the registry redirect it, then log every connection: source IP, time, user agent, and request path. Unique source IPs per day give an estimate of infected hosts, with caveats for NAT and proxies.
Because many victims share an address, the numbers undercount hosts behind a gateway and overcount when addresses rotate. Share lists of source networks with their owners so they can clean up.
Worked example
A researcher registers 3 of the 500 domains a banking trojan generates for a single day, and points them at a logging server. In 24 hours 6,400 distinct IPs connect with the same 42-byte beacon, 31 of them from one university network.
The university's security team receives the IP list and finds laptops with the trojan. The sinkhole served nothing back, so the bots could not receive new instructions from that domain; the other 497 domains were still the attacker's to use.
How it differs
A DGA is how malware picks which domain to call that day; the attacker registers the right one in advance. A sinkhole is the defender's counter: take a name the DGA will produce, or the real C2, so those calls land with you. The DGA creates the candidate list and the sinkhole answers one of them.
Common errors
Counting unique IPs as exactly the number of infected machines. Sinkholing a domain with no plan for the privacy of the logs. Pointing it at a server that replies and accidentally commands the bots. Not telling the network owners. Assuming one sinkholed domain shuts the botnet.
In practice
You will rarely run one yourself. If one of your hosts talks to a known sinkhole address, treat that host as infected, because the sinkhole list tells you who called. Check DNS logs for lookups of listed domains and isolate the machine.