The NetCAT is out of the bag: Intel chipset exploited to sniff SSH passwords as they're typed over the network

A tcpdump type of utility can give you drstination address and port, the ssh content is encrypted but (unless youre forwarding multiple things over one ssh connection) that'll probably do it for throwing out irrelevant packets for timing analysis.

