Sshguard monitors services through their logging
activity. It reacts to messages about dangerous
activity by blocking the source address with the
local firewall. Sshguard employs a clever parser
that can transparently recognize several logging
formats at once (syslog, syslog-ng, metalog,
multilog, raw messages), and detects attacks for
many services out of the box, including SSH,
several ftpds, and dovecot. It can operate all the
major firewalling systems, and features support
for IPv6, whitelisting, suspension, and log
message authentication.