(new ?) efficient attack against an exit relay

Today I was faced by an DDoS attack which looks different from all the ones I observed in former times.

Former attacks shows a characteristic where the malicious IN traffic was just on top of the usual network load (as seen in https://www.zwiebeltoralf.de/torserver/graph.png). The attack today looks like that the IN traffic supersedes the usual network load completely (https://www.zwiebeltoralf.de/torserver/graph.svg).

The system is a stable hardened Gentoo Linux with latest kernel.