At my last gig, I had thousands of domains and hundreds of servers running on every major (and a shitload of minor) service provider. I custom scripted all these servers to compile all the IP's that attempted a connection, send those lists back to HQ, and then distribute back to each node a block-list table that I could dynamically apply to each edge device. One compromised computer even trying to login was completely blocked from 5000+ domains within 15 minutes.
I'm not worried about my ssh login being brute-forced, but if your computer is compromised I want nothing to do with you.