I'd go one better and say get something with actual firewall functionality instead of just a NAT router. I've heard a lot of good feedback about the Ubiquiti Edgerouter lines and they're pretty well priced. Personally though, I use pfSense. In addition to running Snort IDS on it, it let me configure dynamic IP list downloads for known malware sites and have them automatically blocked from my network.
Bookmarks