The major crawlers should respect robots.txt, so you can put directives there to restrict access by useragent. For other types of traffic, look into rate limiting and throttling settings on your web server. Apache has mod_evasive, for example, and others should have similar features. Since it is a VPS, your hosting company should also have some protections in place such as a load balancer or firewall that has some way to throttle requests to your VPS. If the traffic is malicious, they should be able to filter it based on IP or region. If it is legitimate traffic, you should consider upgrading to a more scalable setup, for example several servers behind a load balancer, maybe with some way to programmatically add servers based on load. This is easy to do with Amazon EC2, ELB, and cloudwatch