with currently filter rule in ROS can detect and prevent some of attack like DOS and DDOS
http://forum.mikrotik.com/t/ddos-story-or-warning-use-conection-limit-with-caution/49743/1
i suggest add new future for detect and prevent malware and suspicious traffic and … with pattern like snort database.