Should "change ssh port" even really be on the list?
The little malicious traffic you experience by having ssh on port 22 is dealt with by denyhosts, the attacker would not be able to get in and they would never be able to try again from the same host.
Oddly enough, I have also run across networks where outbound port 22 was blocked. Handy for that too.