I have a fail2ban ban - quite active - based on this: failregex = ^%(__prefix_line)sdisconnect from \S+\[<HOST>\] (ehlo|helo)=\d+ .*auth=0/\d
See also http://www.postfix.org/announcements/postfix-3.0.0.html. (I whitelist a few ips that are our own, or known to run auth tests).