Jim, I think I love you. (Also, I've got some kind of handle on the innards of the boot process on those things. It's pretty cthuhloid. (I've also tried to get Copland running on some real hardware, soooooo...))
And yeah, "oh, it's ddos" is kind of hard to determine from a user-facing standpoint.
From an administrative standpoint, you've really got to have a handle on how the network works. I heard a rumor that the FA admins are using my network diagram (y'know, the one I posted here, on this TROLL SITE) as an authoritative source, so I'm going to assume they don't know how their own network functions. Combined with the "we see packets but don't know where they're coming from", welp.