On my side, our experience with flowspec was not perfect, although arguably it was 10 years ago:
https://blog.cloudflare.com/todays-outage-post-mortem-82515/
https://blog.cloudflare.com/analysis-of-todays-centurylink-l...
https://blog.cloudflare.com/reflections-on-reflections/
> Unfortunately, due to performance and security concerns only a handful of large ISP's allow inter-AS flowspec rules. Still - it's worth a try. Check if your ISP is willing to accept flowspec from your BGP router!
Flowspec as a vocabulary allowing users to deploy rules between Autonomus Systems seem to have failed. It is still super useful, mostly within a single AS, if used carefully.
Instead of focusing on flowspec, at Cloudflare we invested in BPF and XDP. We deploy powerful rules on our Linux servers. The flexibility of programmable BPF is light years ahead of anything traditional routers can deliver. Anyhow: there are many ways of doing detection and mitigation, and there is no one right answer. For us BPF did the trick.
SYN matching https://blog.cloudflare.com/introducing-the-p0f-bpf-compiler...
DNS matching https://blog.cloudflare.com/introducing-the-bpf-tools/