A long time ago I used to have a general purpose server on a DSL line with port 22 open. I thought everything was fairly secure, patched up, etc... I never thought brute forcers would be able to guess one of my accounts (which was a friend's account actually). The kicker? The password was the username. I found out about the rootkit a few days after they got in. I tell ya, kids these days just don't know how to hide a…
For brute forcing, without resorting to port knocking, fail2ban works well and has a pluggable system to handle more than ssh.
I've noticed a few attacks that seem to be orchestrated from the same people but using different IPs.