It's a hierarchy:
1. IP and network rate limiting.
2. Paid access.
3. WoT minimum rank (so they are not hot keys generated just right now.)
4. If they have a low rank and high potential to spam, we slow them down rapidly.
5. Event classification service would report if its repeated and we immediately ban them. Also, report events are supported so people can report as well.
Spamming such systems would be very hard.
The wine approach is also seems interesting but I need to take deeper look. You may want to start a repository or resource of different nostr spam protection models?