fail2ban comes to mind (ipset + iptables + logscanner). http://www.fail2ban.org/ Posted at Nginx Forum: https://forum.nginx.org/read.php?2,270680,271131#msg-271131