I see bot activity cycle up and down based on new groups deploying new C&C/malware. They come and go as malware networks come and go.
For what it's worth, one can quiet down fail2ban by using generalization rules to knock out many of the bots. For example, many of the bots do not set MSS at all or have odd MSS values because they are traversing proxies/vpn's. Another interesting feature of some of these bots is their source port ephemeral range is set to 1-65535 I assume so they can open many connections.
Verify your connections and legit connections are using an MSS of 1460:
tcpdump -p -i any -NNnnt -c100 proto 6 and 'tcp[13] == 2'
So after verifying that all your legit connections to SSH are using say mss 1460, then drop anything outside of that. One can always insert rules above to allow lower MSS for specific subnets or IP addresses. I've noticed most of the bots coming from Asia have an MSS of 1398 and Russia 1424. Some Cisco VPNs are 1454. One could add
! -s your.home.ip.address to exclude your home while testing this. Using the raw table keeps these hits off your state-table and lowers CPU usage.
iptables -t raw -I PREROUTING -m tcp -p tcp --dport 22 -tcp-flags FIN,SYN,RST,ACK SYN -m tcpmss ! --mss 1460 -j DROP
Or if your cell phone uses a lower MSS to reach your server, maybe 1424 and you dont want to explicitly trust that network, then widen the rule with:
iptables -t raw -I PREROUTING -m tcp -p tcp --dport 22 -tcp-flags FIN,SYN,RST,ACK SYN -m tcpmss ! --mss 1424:1460 -j DROP
Using low ports in the ephemeral range is not a violation but tells me these are not normal people so I nuke them as well. This isn't for everyone.
# allow 4 connections per /16 to ssh that have a normal ephemeral port range.
# insert rules above this for trusted networks with a higher limit. Adjust as required.
iptables -I INPUT -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 22 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-upto 4 --connlimit-mask 16 --connlimit-saddr -j ACCEPT
To further remove noise, move sshd to a high port. This is not a security feature but a noise removal feature. It won't stop a targeted attack but will stop 99%+ of the noise. Not in 20 years has anyone hit my ssh port with exception to my public SFTP servers.
If you want to watch the bot activity and see the lack of MSS on most of the connections, use:
tcpdump -p -i any -NNnnt -c800 proto 6 and 'tcp[13] == 2'