I recommend that when your server is back onlien, you do a scan for rootkits.
I think that an high volume of incoming packets does not mean automatically that your server is highjacked. It depends on the port. If e.g. a high number of packets where send to port 80, its an DOS attack but it does not mean that your apache has been highjacked.