u can try out the wid the link given below
http://www.jguru.com/faq/view.jsp?EID=1045412
to certain extent extracting NTLM login from request Autherization header is a gud bid however the method itself has its own loop holes as there are cases that it would not work well with POST method requests.
for better understanding try following few earlier posts
http://forum.java.sun.com/thread.jspa?threadID=349187&tstart=0
http://forum.java.sun.com/thread.jspa?forumID=51&threadID=618236
REGARDS,
RaHuL