We have been using DPS from Terabit Security for about 2 months for early detection of DDoS attacks towards our customers.
Currently we are monitoring ~ 1000 subnets and using traffic samples collected via sFlowv5 protocol configured on our core switches.
The DPS is running on a virtual server with 1 CPU core (Intel(R) Xeon(R) CPU E5-2620 v3 @ 2.40GHz) and 4 Gbps of RAM.
We are monitoring only incoming traffic and do not use any scripts, bgp announcement, etc. At the moment we use it as notification tool only.
DPS is great tool, efficient and reliable. Its installation is easy as a,b,c.