Since most of the grid attacks involve self replicating objects which swamp various grid resources, how about having each sim watch the rate of prim creation and it's acceleration?
The idea is that this could be done in each individual sim so it's scalable, and would act as an alarm. This would be used to trigger more detailed automatic (or human) analysis that couldn't be used normally. For example, are the new prims on the owner's property, are they all from one owner, are they attempting to leave the local sim, etc. - there are lots of possible tests.
If the tests fail, the sim could take counter measures such as slowing down the rate of prim creation and handoff of prims to other sims. It would also allow notification of people who could look at it more closely after the potential infection was contained so it wouldn't be so time critical.
A more general idea is to look at other sim resources and trigger on any rapid increase that persists for some length of time, rate of prim creation though seems like a good start.