It seams to me that this problem was addressed before, back in 2007. Although no one has
disclosed how the attack works, but it is very likely that the issue is the same: clients keep
the same source port for every query.
http://www.trusteer.com/bind9dns