Good idea. Doesn't have to be complex - even java hash code with modulus would work.
OP mentioned the attack is easily identified so legitimate traffic gets served correctly bad traffic gets "logged in" to the poisoned honeypot. 301 after login perhaps