Tools like these are essential if you have Internet-facing SSH services.
If you do not need Internet-facing SSH, do not enable it. It can be an attack vector and there are hundreds of bots that will try to brute-force access within minutes of opening Internet-facing SSH daemon.
Best practices for Internet-facing SSH:
- run on non-standard port (not port 22)
- disable passwords, use SSH passkeys instead: https://www.techrepublic.com/article/how-to-setup-ssh-key-au...
- disable root SSH login
- run fail2ban, sshguard, or similar "block IP addresses for suspicious activity" services
- setup port knocking: https://www.tecmint.com/port-knocking-to-secure-ssh/
edit:
- run WireGuard VPN (https://en.wikipedia.org/wiki/WireGuard) for defense-in-depth