Next level: let them login and forward the ssh connection to the digital equivalent of a room full of mirrors.
https://www.linuxtopia.org/Linux_Firewall_iptables/x4448.htm...
For example, if an attack could spoof traffic to get two different reflectors hall-of-mirror-ing each other, or using a botnet that spoofs traffic to get one collection of dupes to slam a single victim in response, etc.