hmm, apart from ttl, you can use other tcp fields e.g. windows, tcp-options, packet-length etc. then, from a captured trace run passive os fingerprinting to find out with reasonable certainty the device generating the traffic.
these can/may be manipulated via ip-tables, but then you still have a huge data-volume to account for...