They are just probing but better to not give them the ability to do so at all. Port knocking makes sure that even if there is a vulnerability in SSH then you're safe.
Well OK, I suppose it's useful if you're worried about a new SSH vulnerability being found.
Exploits have been found. If nothing else, it'll save you from trawling through page after page of invalid attempts in the logs.