a nice Microsoft TechNet Paper:

strategy that uses HTTP 1.1 host headers to divert port 80 attacks away from unsecured public Web sites into a dead end where they can't do damage

* Prevent automated attacks from reaching legitimate Web domains
* Automatically divert attacks into a dead end
* Get a single log that shows all attack traffic

http://www.microsoft.com/technet/technetma...er/default.aspx