There is one big name company that is always listed on my http connections, they have 4 primary servers - and can hop to others if you block theirs. They can disrupt me but with an active firewall, the moment they try any I/O they get dropped. They used to trace my http back, and then begin searching for open ports using about 10 to 20 different connections from the same server, and tie up all my resources. This might not make scientific sense, but it does happen.The syn floods have stopped as well. Some time nusiance seems the objective - for me. But I am certain ther are cataloguing and planting bots for all those happy-go-lucky users without a care.