Majority of our customers use our hardware end traffic filtering to detect and filter suspicious traffic. The device learns the interaction of the visitor with ad system and if it detects any suspicious activity it will initiate a block. This is done through the use of Cisco, WatchGuard, Corero, and RioRey. You could try looking at CloudFlare