They will brute force no matter what---kids from the University of Beijing, China (or a server there being used as a proxy) usually. Just make a strong password, and turn it off when you don't need it. Or, make the port mapping use a different port, like 2121. You could make acl's in the router to allow only certain people, but if anyone has access, then that won't work. Also, there is CAR/policy maps to limit bandwidth for FTP. I turn mine off during the day myself---not too worried about it. Not much on the ftp server, and acl's to block everyone from hopping from the ftp server to anywhere else in my network.
Burt