In addition to the already mentioned measures, a very simple one is to change the standard ssh
port 22. Since I did it last year I had not a single attempt, instead of several tens per
day.
Brute-Force SSH Server Attacks Surge (InformationWeek)
Posted May 14, 2008 18:42 UTC (Wed) by smoogen (subscriber, #97)
[Link]
This works for small servers very well. For larger targets it only delays the attacks. Moving
the ssh to port 9223 or some such on machine www.bigsite.com stopped the main robots but after
a bit a new set of people showed up with bots after they had done a nmap. I am guessing they
saw it and then told their bot-herd to go after the hi-port. However the small home machine I
have, has never had a scan go high.