Are they accessing pages, or just opening connections? Use netstat to see what state the connections are in.
Make sure syncookies are enabled if they are just opening lots of connections (http://cr.yp.to/syncookies.html).
You can limit parallel connections per host with iptables. See 'connlimit'. Drop any invalid SYN packets. There's also 'recent' which you can use to keep a dynamic list of ip addresses sending n SYNs over the past m seconds (then drop new connections). Bonus is that's the list of IPs is accessible/modifiable from /proc. Be careful not to kick out legitimate clients by setting too low a limit, though. Iptables can log, too, so maybe you can sample connections for a few seconds, 'sort | uniq -c' the ips, and decide on a cutoff.
There are also network appliances that will do similar things without loading your web server.
SHOW PROCESSLIST on your mysql, figure out what queries are happening. It could just be that you need a new index, more appropriate configuration, or better queries. In any case, at least it will give you a clue as to what is causing the load.
Use mod_status (or similar for your web server) to figure out what your Apache workers are doing. Modify keep-alive times.
If all else fails, see if your ISP can enable TCP Intercept on your nearest router. (http://www.cisco.com/univercd/cc/td/doc/product/software/ios...).