rule 1: if you are connected to the net, you WILL be probed.  Period.  There are no guarantees of access, throughput, or that a weakness in your system, as defined by the services you are exposing, will not be exploited if a vulnerability is found.

So, minimize the attack surface: shut off unnecessary inbound services, monitor your logs, configure any firewalls you may have correctly, keep your system patched, keep your application patched.  Other than that, unless it's egregious, ongoing, and constant, your ISP is innundated with hundreds of complaints daily about this activity, so, they will typically, unless you're a commercial customer with a 4K monthly bill, put you at the bottom of the list for detailed investigation. 

That's just for starters.  All you can do is all the right things: minimize attack surface, keep patches current, monitor your logs for suspicious activity, adopt a stance regarding applications of 'that which is not expressly permitted is prohibited', and realize that, in the general scheme of things, amateur radio repeater linking is not a high priority, national security, launch code, or life safety (really) infrastructure.

And remember, it's not personal...on the part of the hackers...it's just business.

Bryan
> Anyone else been experiencing DOS attacks on their nodes? Been having issues with at least two of my nodes, and I know one other person as well. 
> Symptoms to look out for are a sudden degradation in your internet service that your node is attached to, steady it very active internet light on your router if you have one, major breakup in communications, pings to public ip addresses results show major packet loss, can't get registered on Allstar. 
> Just to name a few. 
> Please contact me directly if you have encountered this issue. 
Lu
