I think you may be on on to something the honeypot server...you could create something like Slowloris in reverse. One of the techniques it uses is to send a request one. Byte. At. A. Time. Very. Slowly. You could try doing the same thing with responses from your honeypot, which, assuming they don't give up before they get the full response, could even be redirects back to the honeypot.
But if you can ID them easily then iptables rules might be the most effective use of your time, especially if you can use fail2ban, which makes the whole process very easy.
The TLS thing is interesting, but if some of this traffic is coming from compromised devices it would probably be less harmful for the owner of the device if you didn't make them burn a ton of CPU cycles.