Suggestions for how to limit DDOS / multiple directory URL attempt

Today we had a bunch of hits and errors related to someone accessing a URL that looks like:\..\..\..\..\..\..\.

Any ideas on best way to prevent this type of sniff/attack scenario?


What WAF rules do you have enabled? I imagine that sort of request would be blocked by the managed rules.

