(Edit: For what it's worth, when I tried out knockd, it supported arbritrary port sequences, so you could easily have a 16 port sequence, making it as robust as you want. Timing however, was quite a pain. I had to use specific timeouts (relative to the RTT time from my network to my VPS), and manually enter each port in the sequence).
Personally, I've found that whitelisting IP's for SSH access, as well as a default block-all policy, disabled root login, and Key authentication have been enough to keep people out of my VPS.
Sure, seeing all of the denied traffic in the logs is annoying, but there's not much you can do about that (other than not log it).