Why not just outright ban the use of normal SSH and enforce all legitimate SSH activity to go through a wrapper program that reports to a monitoring service?
It could be a 4-line bash alias, any SSH activity that doesn't go through your wrapper could be considered suspicious