My ddos protection in the last years was not being competitive. Do not host the mainstream stuff and you should be fine.
Otherwise you can try analyzing the attacking traffic using tshark for example and try playing around with firewall rules. But I never did that because my plan A was working pretty good :p