Actually, I've looked into this. I've found a few solutions that modify the kernel, but they're really, really old. If I can't get this working, I'll probably end up using a netfilter patch that allows me to match the owner on incoming packets as well (owner-socketinfo, I think).
But, don't iptables counts reset after a while?