As the other commenter said, there's nothing you can do to prevent brute forcing. What you can do, is have a very expensive KDF. So for every password you enter the wallet will take a very long time to 'unlock', which is basically the process of deriving the key from the input.
'Expensive KDF' sounds cryptic, but often just having some memory/CPU requirements for an instance of the KDF should suffice.
Fun fact: There is a reason why when you enter a wrong password for `su` or `sudo` it seems to take longer to throw the wrong password dialogue than to log you in. That's because the password authentication module (called PAM) artificially delays you to prevent brute forcing. You can go and change it if you want. (I would discourage it)
Of course, this won't stop everyone. One can just put the harddrive in a different computer to get the hash of the password and crack it within a day with proper resources. This is the problem with trying to 'stop' bruteforcing at the input level. You must already asssume the attacker has the hash, then the difficulty must be determined. That's the point of people arguing about password hashes (for fun, of course)