We first started experimenting with the storm botnet about six months before doing this experiment. Once we realized what their architecture allowed us to do (MITM on the botnet's C&C), it probably only took a month or two to put together the infrastructure needed to conduct the experiment. Scaling to more nodes would have been relatively trivial, as the VMs running the Storm nodes were completely unmodified and we could have easily brought more online behind our flow-modifying router if necessary.
A colleague of mine did come up with one idea called "botnet judo" (paper here: http://www.cs.ucsd.edu/~voelker/pubs/judo-ndss10.pdf) whereby we run spamming bots within a contained environment that "seems" to have SMTP connectivity but actually just sinkholes all the spam, and then we developed highly effective and specific regular expressions from each bot's spam corpus.