I have noticed a pattern. It seems in the morning (approx. 4-9AM EST), the DoS attacks aren't occurring. We can rule out most of Asia and Australia as the source of the DoS attacks in this situation. That means that the DoS or DDoS attacks are likely within Europe, Africa, South America, or North America. For DoS we'd just have to guess, although request intervals should give them away. As for the DDoS botnets, I'd do an IP lookup on these countries - If we are lucky, we will find that most of the botnet IPs nearly match in number, aside from the last digit - Hackers and spammers are often smart enough to not use the botnet farms that share these IPs, unlike the kiddies and the tools they download.