Apache logs show both (a) the authenticated member name and (b) the size of the object it has delivered. It shouldn't be hard to write a script that continuously "tails" the logs and keeps stats on how much each member has downloaded. You could then set up something to modify/rewrite htaccess to redirect any further requests from that member to a page explaining that they've exceeded their quota.
Are you actually having a problem with excessive downloads or are you just being careful? Sometimes pissing off members may cost you more than savings in bw.
