I'd like to see more of a legal response.
First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, harassment, Computer Fraud and Abuse act violation... Maybe a restraining order prohibiting the sale of "smart TV" known to be able to host attacks. Have imports seized by Customs and Border Protection. That would get a manufacturer's attention.
The manufacturer's EULA will not help the manufacturer, because the plaintiff, the party being attacked, is not a party to the EULA at all.
The problem is most of the botnet zombies are in places with very little rule of law like eastern europe/russia/south america/china. It is an exercise in futility and the richest customers just opt to just spend money on more protection than shutting down the zombies.
If the zombie is in the US, hosts like Google or Amazon will take 1+ month to respond.
I'd love to see China and Russia sued for hammering my personal websites for the past 20 years... will it ever happen? Hell no, LOL.
Man, it wasn't until reading this that I realised I could get sexually aroused by the mere prospect of legal / governmental competence.
I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort.
Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I think it was in the GamerNexus investigation on the whole LG Tv spying on people IIRC.