iptables
- since ~20y undocumented feature (meanwhile maybe well): beside
DROPandREJECTthere is alsoTARPITto keep a malicious host busy as long as possible
DROP and REJECT there is also TARPIT to keep a malicious host busy as long as possible