Funnily enough I was just searching for the same thing myself yesterday. I managed to find this old article
which seems to suggest that this may be someone trying to force your server to contribute to a DDOS attack on another server, in your case isc.org. By submitting a request that appears to come from 220.127.116.11, they hope to flood 18.104.22.168 with replies that it didn't ask for. If I'm understanding this correctly, and I hope someone will tell me if I'm not!, the fact that the slog say 'denied' means that your nameserver didn't allow a recursive DNS query, which is as it should be, and there is no cause for alarm. Everything is working as it should. At least that's how I understood it.
Hope this helps!