I think about this sometimes. Shouldn't there be a way for your app server to report to your DoS protection service which requests are abusive and which are legit? Like a fail2ban but distributed: if someone connects and sends invalid credentials, block them at the ISP or proxy level, not on your host's firewall.
It's possible that this doesn't exist for good reasons though, I am not sure how the numbers work out in terms of relative capacity.