If you could get SSH to negotiate the upgrade header before initializing its own connection, then you probably could.
I think this could also potentially be done via iptables rules as well, since iptables is capable of inspecting & rerouting packets.
A little known fact is that newer versions of openssh support ProxyUseFDPass which allows you to do some protocol negotiation before passing the socket onto to the regular client. http://www.openssh.com/txt/release-6.5
Nice. I'd love to see that in practice. Might have to dig into that myself...