I am more into nftables now-a-days (which just had release 0.8 in the last couple days), but maybe these iptables/xtaqbles thingies can be made to work in nftables:
- Xtables-Addons On Centos 6 & Iptables GeoIP Filtering
- search for 'tarpit nftables' and see if there is anything, it is an interesting sticky concept
- A series of Xtables-addons. It would be interesting which of them could be re-implemented with nftables functionality.