Handle with ddos or many flows?

You could try to activate a Blacklist Filter like for example http://forum.mikrotik.com/t/blacklist-filter-development-topic/121264/1 I’m using a similar solution for some customers and it works very well.