GeoIP has this located in France. (First problem... French ISPs suck hardcore) It looks like the client is sending a 66 byte packet and getting no response.
I would code in a couple of retries into the auth routine or maybe an alternate routine that uses an authentication hash/cookie that requires no active re-key or re-auth.
Arbor Peakflow SP is the product that these DDOS providers use. The best provider IMO is Prolexic (owned by Akamai who has a huge global presents).