Hi there,
in case that public key authentication is used (and passwords are disabled) the SSH server should drop the connection immediately if no public key is provided by the client (instead of asking for a password and denying access even if a valid password is provided). I have thousands of failed login attempts (from different IPs), all trying to login as admin, user, test, etc. using passwords.