I am running iptables (SME is a RH7.3 derivative). I'll look into this. It doesn't cover the mail/web server hits, but it is a start.
Right. The iptables limit module is good for throttling iptables logging, but what we need is something to block application (Apache, sendmail) logging by dynamically firewalling misbehaved clients (eg. zombies).