A watermarking-based host correlation detection method is proposed in this paper. The idea is to embed some unique watermark into the flow by slightly adjusting the timing of selected packets in the flow. In the embedding phase, we use network flow grouping strategy to divide the IPDs (i.e., interpacket delay) into two different groups randomly, and then realize the watermark embedding by utilizing the relationship of the average value of IPDs in different groups. The detection scheme we proposed not only has the advantage of the timing based scheme, but also has a higher robustness against timing perturbation attack.