Most operators are probably running HTTP proxies (transparent or otherwise) and checking user agent strings in the logs would be trivial. Running something like p0f to fingerprint hosts is also quite easy.