I've been using Linode as long as they existed. When they were small I would have been curious about the details of your experience, but they have grown and many of the original folks appear to be less engaged in the community so boiler plate automation does not surprise me. I would guess that if you spoke with them on the phone you may get better results, but I also suspect they would try to sell you a DDoS solution. It would be a very unfortunate coincidence if people started receiving attacks after a CDN/DDoS mitigation service acquired them. A similar pattern occurred when Neustar/UltraDNS started selling DDoS mitigating services.
Out of curiosity, what types of attacks are you receiving?
e.g.
- packet rate / packets-per-second
TIMEFORMAT=%R time tcpdump -i any -NNnnt -p -c1000 not port 22 >/dev/null
- average mss of the tcp syn packets / number of tcp syn's missing mss.
tcpdump -p -i any -NNnnt -c500 proto 6 and 'tcp[13] == 2'
- average length of the udp packets
iptraf-ng -z eth0 # or # tcpdump -p -i any -NNnnt -c500 proto 17
- NIC saturating volumetric attack?
iftop -i eth0 -PNnBb -f 'not port 22'
- Number of AS numbers these are distributed across or is it literally just Linode AS?
Replace port 22 with whatever port you are running sshd on.
I ask because I have seen an uptick in incredibly odd port scans that seem to just repeat. They are harmless but make tcpdump really noisy. If you give me some general numbers on the above questions I might be able to suggest some generalized mitigations assuming the numbers are small enough. Most that I am seeing come from 103/8, some from a server reseller in the Netherlands and some come from Tor exit nodes suggesting to me someone is trying to break Tor. This is not specific to Linode, I am seeing this on 3 VPS providers. Maybe 2% of the source IP's I see are coming from Linode.
If most of what you are seeing are TCP packets missing mss, take a look at this thread [1]. If most of the packets are UDP, first look at the legit size of UDP packets of the applications on your server, then use the "length" iptables module to DROP anything that does not match your traffic pattern, ideally in the raw table to keep the odd bots off your nf_conntrack state table.
[1] - https://news.ycombinator.com/item?id=33129508