DDoS story, or WARNING: use 'conection-limit' with caution!

If someone has a BGP session with the peer - you can try to set up BGP blackholes and ban the IPs at the upstreams.
I wrote a helper to do that: http://forum.mikrotik.com/t/advanced-ban-own-ddosed-ips-using-bgp-blackhole-updates/145280/1