First of all, do not block the account, if someone gets into the cap, offer her reCaptcha .
$_SESSION , cookie. - /, cookie $_SESSION. . , , ip, timestamp. timestamp . - ,
select count(ip) from brute_force_protection where DATE_SUB(NOW(),INTERVAL 1 DAY)>=timestamp and ip='".$_SERVER['remote_addr']."'
, 3, ip. mysql_real_escape_string() remote_addr, apache TCP-, , ( extract()).
EDIT:
ip- , . - -, , .