I have on-demand dynamic IP, an SPI hardware firewall and I generally block all cookies until I need to login somewhere that requires them.
Even then I still had some idiots in Guangdong Province trying to run port probes etc. Finally in desperation I setup a 1200 byte ping with zero inter-ping delay and left it running for a week or so against their IP not really expecting it to have any effect. They did stop port probing my IP however. Of course they were probably probing a whole range of class-A addresses.
Someday I'm going to just block anything from chinese IP prefixes.