I wrote a bit about how I configure OpenSSH to make it less susceptible to break-in via password guessing.