Depends on the attack and how sophisticated it is. For most layer 7 attacks like this one, you can filter e.g. specific user agents or protocols. One thing that often works (but has some false positives with simpler search engines) is dropping all HTTP/1.0 traffic, because any remotely modern browser uses HTTP/1.1. Essentially you block anything that's unusual, like specific user agents (reflected attacks from user agents containing 'Wordpress' and 'PHP' come to mind a lot especially), HTTP headers, and so forth. Ideally as far upstream as possible, but it can be done on the server level as long as you have enough horsepower to throw at iptables or the web server, and your connection doesn't get saturated. The right IP blacklists can help a lot as well.