If you're small (as in you don't have your own blocks) , you are going to have to rely on your upstream provider to head off most of the volumetric stuff. If practical you may also want to switch to a deny all posture and only allow a whitelist of known clients, although this is easier said than...