Hello,
Unfortunately with SSG5/SSG140, you will need to block the traffic upstream.
Juniper SRX devices give you an option of 'firewall filters' which can be applied to interfaces to block such traffic rather that letting it get processed till policy lookup.
Even ISGs and NS5000 devices have CPU protection but not SSG5/SSG140 to block the traffic destined to the device on the same device.
Regards,
Rushi