Fair point, so to make this successful you would have to do UDP packet inspection on egress from your network to localize to the connection into your network where someone is spoofing source IPs. Clearly you can't do that on peering points (whose to say it is or isn't legit) but certainly from the ISP's connections into the Tier2 that could highlight bad ISPs and if those ISPs don't play ball you can cut them off from network access.