I agree, however if the appliance resources are monitored correctly, and over time, you would easily know what is deemed normal traffic, and this would trigger an investigation.
I tend to aim for 50 - 60% peak CPU utilization, during the working week, if it goes above this, and when it does it tends to be pretty obvious I would be all over it.
In past cases it generally some new service that's been rolled out that's not working correctly or another country going through the UK firewalls to reach the internet as an example when they should be going out there local country POP.
CPView can help to determine to IPs, and I know there are utilities on checkmates (Phoneboy has mentioned this in later comments) that can help define top ten IP as example, equal NMS's monitoring the appliances could glean this information via SNMP as well.