I am exploring using mod_security with OWASP CRS ruleset on my apache-CentOS server. In general, do such firewalls are any good in mitigating potential invalid (user/bot) activity? Especially will such firewalls offer a layer of protection for adsense or other third party ads? Do you use such firewalls (any for that matter)?