Hello,
Last time I checked, on branch SRX kit, lo0 filter is executed last after:
1/ interface input filter
2/ host-inbound-traffic config
3/ junos-host policy (if You have one).
So, if You don't have (1) and You are flooded by huge variety of ICMP flows (or UDP, or whatever), then Your flow table is going to be under stress.
So, I would recommend to configure stateless interface input filter, rather than relying on lo0 filter or stateful firewall capabilities to protect self.
HTH
Thx
Alex