Most clients participating in DDoS attacks are plain dumb.
They will continually perform a GET request on a single page and not parse the response. This means they wont respond to javascript, images, cookies or redirects correctly.
You can devise a test that identifies attacking clients and then blacklist the IP addresses for a while.
While I'm sure this strategy isn't perfect, it has been sufficient for the two attacks I have been subjected to.
Edit: vladd's reply articulates this idea better than I was able to :)