Hi,
there is no 1 to 1 correspondence of this ScreenOS feature in JUNOS. You have to write a firewall filter and bind it to the loopback interface (lo0.0). You don't have to assign an IP address to the loopback interface.
In the firewall filter you could have terms like accept all incoming SSH connections from a specific prefix list and in the next term, you could drop SSH from all sources.
Be careful if you don't allow all other traffic at the end because every host inbound traffic (like ICMP, OSPF, etc.) runs through this filter. So it is not uncommon to have an allow all term at the end although this is usually not best practice in IT security.
Kind regards,
Dominik