You are right, keys are used in the OP, not sure then why you'd use fail2ban for ssh but OK.
Regarding the sysctl entries, I reviewed them down to execshield (after that there are tweaking entries) in a Amazon EC2 vanilla Ubuntu distro and all the entries are the same except log_martian (debatable, again, are you going to look at the logs, if then what are you going to do with them) and accept_redirects. Execshield is a RedHat thing, it's not used in Ubuntu.