On my web sites, anyone logging in with an invalid userid locks that IP address out for a few days. But people have figured that out, and I get strings of attempted log ins using the same bogus userid from 40 or 50 different IP addresses in the space of a few minutes. I also use whitelists of trusted IP addresses that avoid those hurdles, but I use them sparingly and watch the logs.