الدرس 7 من 8 · 7 دقيقة
Seeing the network: threat visualisation and its limits
A map of live connections turns thousands of log lines into something a person can read at a glance. Learn what visualisation is good for, why IP geolocation is only approximate, and how to read FireAI’s world map without over-reading it.
هذه الصفحة متاحة بالإنجليزية حاليًا.
A busy Mac opens thousands of connections a day. As a log, that is a wall of addresses, ports and timestamps that very few people will ever read. NIST SP 800-92, the guide to log management, points out that the hard part of logging is not collecting data but analysing it: logs only help if someone can find what matters in them. Visualisation is one of the oldest answers to that problem. The human eye is very good at spotting the one line that does not look like the others.
What a visual view is good for
- Orientation: seeing at once which apps talk the most and to whom.
- Outliers: a new destination, an unexpected country, a burst of traffic from an app that is usually quiet.
- Blocked versus allowed: whether your rules are doing what you think.
- Conversation: a picture is easier to show a colleague or a family member than a log file.
What it is not good for is proof. A dot on a map is a starting point for a question, not an answer. The investigation still happens in the details: which app, which name, which rule, how much data, and when. NIST’s incident response guidance (SP 800-61) frames detection the same way, as signals that must be analysed and confirmed before anyone acts on them.
Why IP geolocation is approximate
A map needs a place for every IP address, and the internet does not provide one. Geolocation databases are built from registry records, network operators’ own published data (RFC 8805 defines a format for that) and measurements. They are often good at country level and much weaker at city level. Three things commonly mislead:
- Anycast and content delivery networks: the same address is announced from many sites around the world (RFC 4786), so traffic goes to the site nearest you. Big providers therefore often appear “next door”, whatever their headquarters.
- Cloud hosting: an address shows where a server is hosted, not who owns the data or the company behind the app.
- Proxies, VPNs and relays: traffic can be deliberately routed through another country (MITRE ATT&CK T1090, Proxy), so the last hop is not the origin.
The practical rule: use country and company as hints, and use the app identity and the host name for decisions. “An unsigned tool I don’t recognise sent a lot of data to a name on a threat list” is evidence. “There is a line to a country I did not expect” is a question.
How FireAI’s world map works
FireAI’s World map is a live globe of the connections your Mac’s apps make. Each line is a real connection, drawn when it happens, and blocked ones are shown in red.
- Clicking a line or destination opens a card with the app, the company and place when known, whether the connection was allowed or blocked, and a short reason, with buttons to investigate or block it.
- A side panel lists every connection, can be filtered to one app, and can show or hide kinds of traffic: Sign-in, App data, Calls, Media & content, Tracking, and Other.
- Export saves one app’s connections to a file for closer inspection outside FireAI.
- Company logos are opt-in: by default destinations show a monogram and no extra requests are made.
FireAI states the geolocation limit plainly: locations are approximate, big networks such as Google or Cloudflare are drawn at the edge nearest to you rather than at their real building, and if the location database is not installed, places are not shown at all. That honesty matters. A map that pretended to precision it does not have would push people toward wrong conclusions.
From the map, the natural next step is Investigate (see lesson 3), which turns one connection into a list of concrete factors and a risk score. The map finds the question; the investigation answers it.
A good habit is to look at the map when nothing is wrong. Ten quiet minutes on an ordinary day teach you which apps are chatty, which companies they reach and which kinds of traffic dominate. That is your own visual baseline, and it is what makes an unusual line stand out later. When one does, resist the urge to block on sight: open the card, read the app and the reason, and only then decide.
أهم النقاط
- Visualisation helps people notice outliers that a raw log hides.
- A dot on a map starts a question; it does not prove anything.
- IP geolocation is approximate: anycast, CDNs, cloud hosting and proxies all shift the apparent location.
- Decide on app identity, host names and threat lists; treat country as a hint.
- FireAI’s world map draws each live connection, shows blocked ones in red, and says openly that locations are approximate.
اختبر نفسك
1. Why do large services often appear very close to you on a connection map?
- They copy your location
- Anycast and CDNs serve you from the nearest site, so the address geolocates near you — صحيح.
- Maps always use your own location
- They use your Wi-Fi name
With anycast (RFC 4786) the same address is announced from many sites; you reach the nearest one.
2. Which is the strongest basis for blocking a connection?
- The line goes to an unfamiliar country
- The dot is large
- A recognised app identity plus a host name on a threat list you trust — صحيح.
- The connection happened at night
Country is a hint; verified identity and threat intelligence are evidence.
3. What does FireAI show when the location database is not installed?
- Random locations
- Your own location for every connection
- No places at all, rather than guessing — صحيح.
- The company headquarters
Showing nothing is better than showing something wrong.
جرّبها مع FireAI
طبّق هذا الدرس عمليًا على جهاز Mac الخاص بك.
- كيف يراقب FireAI اتصالات جهاز الـ Mac — اعرف أي تطبيق يتحدث مع الإنترنت، بعبارات بسيطة، دون تثبيت أي شيء يعمل كخدمة خلفية مخفية.
- القواعد: تطبيق أو موقع أو نطاق أو IP أو نطاق عناوين، إلى الأبد أو حتى إعادة التشغيل — اكتب قاعدة دقيقة كعنوان واحد أو واسعة كنطاق كامل.
- الطيار الآلي: FireAI يقرر الاتصالات السهلة نيابة عنك — دع FireAI يحسم القرارات السهلة بنفسه، واطّلع دائمًا على السبب.
- فحص عميق، دون فك تشفير أي شيء — احصل على تفاصيل حقيقية عن اتصال آمن دون أن يقرأ FireAI أبدًا ما بداخله.
- أوضاع الأمان: المنزل، المقهى، الحذر الشديد، تحت الهجوم — واءم صرامة FireAI مع مكان جهاز الـ Mac فعليًا، بلمسة واحدة.
- Coffee Shop Armor: safer on public Wi-Fi, and warned about fake networks — Sit down in any café, hotel or airport and let FireAI tighten up for you.
- خريطة العالم — اطّلع على الوجهة الحقيقية لبياناتك، لا مجرد اسم مضيف عليك البحث عنه بنفسك.
- اسأل FireAI: أوامر بلغة بسيطة بدل النماذج — غيّر ما يفعله FireAI بكتابة جملة، لا بالبحث في القوائم.
- تحقيق في اتصال — قرّر بالاستناد إلى الحقائق أمامك، لا إلى تحذير مبهم.
المصادر
- NIST SP 800-92: Guide to Computer Security Log Management
- NIST SP 800-61 Rev. 3: Incident Response Recommendations
- RFC 4786: Operation of Anycast Services
- RFC 8805: A Format for Self-Published IP Geolocation Feeds
- MITRE ATT&CK T1090: Proxy
- FireAI docs: The World map
- FireAI docs: Investigate a connection
طبّق ذلك على جهاز Mac الخاص بك
جرّب كل الميزات مجانًا لمدة 17 يومًا، دون بطاقة.