Anyway, best way to figure out what's going on, is to generate a distinct list of IPs originating the bad traffic from your logs, and block those addresses at your firewall. If this doesn't stop the strange requests in 15 minutes or so, you may want to get some expert help.
Your hosting provider may be able to be of some assistance here, but that greatly depends on their level of clue: many budget providers will just drop you at the first sign of denial-of-service related trouble, so do keep that in mind.
Signing up for a specialized service like Cloudflare is probably your best bet, and should be pretty affordable as well (their web site lists their business plan with "advanced denial of service attack mitigation" as $200/month, and they suggest that if you call them they can have you protected pretty much immediately).