Thanks for the advice :)
I'm looking for a more "fingerprint" like way of separating the hosts, wihout obtaining specific information about the subnet behind the router.
For example, if there was some way of determining that two TCP/IP streams originate from different machines
From what I saw in the literature (e.g. the article sent by digip), there are several possibilities for inspection:
1) TTL and/or IP ID within IP Headers
2) Time information (timestamp?) within TCP Headers
3) Port numbers to see whether the source port number in TCP/UDP packets from a source reaches a high number quickly
For IP-ID it's possible, for example, to plot the values received on a graph, and see how they group together - assuming consecutively-received values sent from the same host are closer to one another that values sent from different hosts
What do you think about this?