Htaccess the directory, but any password past 8 characters is a waste, as it doesnt read past the 8th one.
Use upper and lower case, and put an odd charator in there, something like a # ~ + } should make it almost impossible to ever guess what it is, and trying to brute force it will take weeks. and it wont take long for you to figure out where the attack is coming from and block the IP from the server directly as an other member here suggested.
But good luck, hope you make it though this unscaved.