Would it note be relatively trivial for the manufacturer to just filter incoming requests by whitelist of registered ids of their appliances?
DDoS protection is surprisingly challenging - usually it's relegated to a CDN provider, but that would be more difficult when the actual consumers are the same people most likely to be hosting botnets.