These are good questions!
More and more we have to be watching our internal network as much as our external networks. I think this makes a case for internal IPS such as putting an IPS blade in a Cisco Cat 6500 chassis.
About the second point, the Tier 1 carriers (Sprint, Verizon, AT&T, and others) are all meshed. In the USA, they are "the Internet". That's why these Tier 1 carriers have to have such a strong NOC & SOC (network & security operations centers) - to protect the Internet backbone. Still, I suspect that most of these carriers have such big backbones that they would be able to deliver a DDoS attack, at full speed, to whoever it was targetted to, without ever noticing it. It would be the targets that would be the bottleneck and be denied service.
Thanks for reading my TechRepublic articles!
Keep Up with TechRepublic