Yeah. Unfortunately this is the way they've gone now. The attackers realised that lots of people have a process that will autoblock any IP that does more than a certain number of invalid attempts.

In the end I decided to just disable password entry via SSH and insist on a key only. It will block an IP after the first attempt if it tries to use a password.