These sort of attacks rely on feedback.
Don't give it to them. Lock out the IP after a certain number of failed attempts.
MS provides for this with RDP.