Not to mention that the attacker's DNS resolver could merely ignore the TTL and bombard your DNS server - if that's the weakest link, why even bother with the rest?
Because quite a few companies outsource DNS, and attacking a DNS provider involves many companies. Not to mention the fact that most DNS providers have been attacked before...