- Start with hardening SSH (Client first, then the server) to ensure you do not lock yourself out by selecting ciphers the daemon does not support. [1] This will actually speed up ssh client-server negotiation. Assuming you have a recent version of OpenSSH this will drop the older bots.
- Ensure you have SSH key trusts and then disable password authentication and don't bother blocking anyone. It's just noise and the C&C nodes will just use a different node to reach you.
- If the noise is distracting, move the sshd listener to a high port. This is not security and will not stop a targeted attack, this is just to stop the noise. 99.999% of the bots will just go away. [2] Ensure the port you select is opened on the firewall first.
- Optionally, add CIDR/IP restrictions to your SSH keys if you are concerned that you might leak your private keys somehow. This is done on the server side in the authorized keys file(s) depending on how you configured key trusts. Maybe leave one low-permission account unrestricted in the event you want to access from a cell phone.
grep -i authorized /etc/ssh/sshd_config
AuthorizedKeysFile /etc/ssh/keys/%u
cat /etc/ssh/keys/bender
from="172.16.0.0/12,192.168.0.0/16" ssh-rsa AAAA[snip]... comment
- Very optionally, only permit connections to ssh that have valid MSS. This drops massscan, the most prevalent scanner used by bots. If your clients use jumbo-frames then you may need different values such as 1280:9200. Most home connections will be 1460 and some mobile ipv6ipv4 gateways are 1280 or 1380. Adjust as you see fit after using tcpdump to see valid values vs. bot values.
# see what is valid and invalid by capturing syn packets to 22
tcpdump -p -i any -NNnnt -c512 port 22 and 'tcp[13] == 2'
# limit ssh to a desired mss range.
-A INPUT -m tcp -p tcp --dport 22 --syn -m tcpmss --mss 1280:1460 -j ACCEPT
[1] -
https://www.ssh-audit.com/[2] - My anecdotal experience since the 1990's.