locating attacker
intersting,
what makes you think that?
it may be too late to do anything?
frist thing turn logs on in routers settings, but then you need to understand all that information.
there is no one answer. several steps may be
as for articles do what i do search them, and the form post you need to go through the muck too find the brass.
hit me back with pm if you need!
My server gets scanned 100's of times a day.
Most of the ips in the logs are proxies as you'd except, and only about 5-10% of them link back to a real server where the scans originate from, but almost all of those have been compromised and the scripts/tools have just been left there by someone to carry out automated scans.
Less than 1% of them trace back to an IP that you could quote in a complaint to the ISP who owns it. So if I was you I wouldnt hold my breath waiting on my revenge.