Yes, most of the packets are such. I also thought of virus but source and destination packets are not from same machines. As source and destination both are varying, I ruled out that possibility, However, it might be a smart virus or a group of infected machines. Other thing is that all discovery requests are not for valid IP, It appears like random probing. The problem is our subnet is very large (Thousands of machines) divided in sub-sub-nets of hundreds of machines.
Thanks anyway for suggestions.