My advice would be to consider logging the request headers in iis logs, then consider the possibility of blocking requests based on the specific value of that header, but be careful because request headers can be spoofed.
Its a dificult problem if you can't just block by ip address but it isn't a problem that I expect to solve within Form Wizard Pro.
Best,
Joe