When I owned a much larger vb site, a dedicated Cisco ASA Firewall provided basic protection. When DDOS attacks would happen, my host would move my public network interface (before my firewall) to a special network segment that was equipped with DDOS mitigation technology and let it run there for 24-48 hours. It didn't happen often, but represented the "no additional charge" means of dealing with some mean attacks. At the time, my primary webserver was an Dual Quad Core machine and on some occasions it would be brought to a crawl until mitigation was activated.
There aren't that many service providers who do this, but the idea is catching on. Ask your service provider about it.