Two thresholds at once, /32 and /24
Every destination is budgeted individually and the prefix is budgeted as a whole, evaluated on the same packet. A carpet bomb trips the aggregate even though no host trips its own, and a single-target flood trips the host even though the prefix is quiet.
Your prefixes stay announced
Protected ranges are announced normally and keep working. There is no blackhole community, no null route and no customer taken off the internet as a mitigation step - the thing that makes support tickets and churn.
Per-customer profiles inside one prefix
A game server, a mail host and a backup target in the same /24 have nothing in common in their traffic shape. Thresholds are set per destination against measured baselines rather than one number for the range.
Abuse and reflection controls
Rate limits on answerless DNS responses, suspect query floods and the full reflector set - chargen, CLDAP, rpcbind, memcached, MS-SQL, SSDP, SNMP, NetBIOS, WSD, CoAP - applied per destination /24 so a compromised resolver does not poison the whole range.