Huh, if only there were some way to digitally sign and secure communications, perhaps some sort of... Encryption scheme could be used to ensure accuracy of information...
It's not a sheep vs. goats problem, where you just have to ID those bad machines and block them.
It's a defector problem. Any 'legitimate' machine can join a botnet at any moment, along with all the permissions and trust you vested it with back when you approved of whatever it was doing.
Now if we combined IP addresses and public keys so they were one and the same we might be onto something.