Do you have any 192.168.1.x addresses? If not, block the whole block. If there are no class C RFC1918's,...
access-list 107 deny ip 192.168.0.0 0.0.255.255 any
access-list 107 permit ip any any
or, just tie them into an existing acl, route map, etc. There is MAC address port security, but it can be tedious in mid-to-large networks...
Or, dhcp snooping. Is this in a position where they'd need helper addresses? You could send out an email threatening castration by spoon for whomever does this, and script something that will email you when someone plugs in a rogue device (like any other device), whether it be via SNMP, syslog, AAA accounting, etc.
Burt
Burt