Anonymous's LOIC is a great example of this kind of attack. Essentially, you go for a different kind of amplification than you do with 3/4 attacks -- it's "time amplification", where a small http request can hit a URL and cost huge amounts of time on the server. e.g. an unindexed search. It's actually possible to kill some webapps with a single web browser just by hitting "expensive" URLs repeatedly -- can even be done manually in some cases.
There are a lot of ways to protect against this -- rather than pure pipe capacity, you generally want something like a Web Application Firewall (WAF). You also generally want to tune your web app to expose only "safe" urls, or to put captchas or logins in front of "expensive" URLs.
One could exploit algorithmic complexity attacks, like a bad regexp, but that's usually specific to your own code.