DNS attack?

I had to ssh in and restart named last night and again this morning, as my main DNS box stopped working. Can’t find anthing in the messages log except for DHCP requests, where should I look to see what’s stopping DNS?
I guess the simplest thing would be to set a cron job to restart named every 10 mins until I figure this out…