ICP.Lab Storage & Scalability Summaries

Isn’t 970 updates/s per subnet to prevent DDOS attacks?

The response to DDOS attacks is rate-limited at the IP and Subnet level.
However, my understanding is that in Ethereum, etc., gas fees are charged to contain DDOS attacks themselves, but ICP does not seem to be able to do that because it is reverse gas.
Since DDOS attacks themselves are not prevented, please let me know if it is possible to contain DDOS attacks with these rate limits, or if there is a loophole and they could be attacked, and how Dfinity is handling this area.