Here's a revolutionary idea: fail2ban, but implemented into sshd and enabled by default.
I KNOW, RIGHT?
(Seriously though, why is it not default to have some kind of rate limit on SSH? This would absolutely immediately reduce spam and malware distribution by 84%. Because it's ALWAYS the ones who don't know how to set up fail2ban that use "admin" as a password.)