Dependencies
Installation
1
Install Python
2
Download project
3
Run BlackShield
4
Install ACL files
Configuration
Squid Rules
Modify/etc/squid/squid.conf and add the following rules:
Samba Rules
Modify/etc/samba/smb.conf and add the list to the veto files directive:
Important:
- You cannot include more than one list in
smb.conffor theveto filesdirective - Use the
acl/smb/merge_veto.shscript to merge lists:ransom_veto.txt(updated withblackshield.sh)common_veto.txt(static - add/remove extensions manually)
Iptables Rules (Not Recommended)
Global Variables
Identify your network interface:Hex String Rule
Block malicious hex strings:/var/log/ulog/syslogemu.log):
BitTorrent Rule
Block BitTorrent protocol:/var/log/ulog/syslogemu.log):
Tor Rule
Block Tor connections:/var/log/ulog/syslogemu.log):
ACL Files Reference
Data Sources
Ransomware Extensions
- dannyroemhild - ransomware-fileext-list
- eshlomo1 - Ransomware-NOTE
- giacomoarru - ransomware-extensions-2024
- kinomakino - ransomware_file_extensions
- nspoab - malicious_extensions
Malicious User-Agents
Analysis Tools
String Capture Tools
- tcpdump - Network packet analyzer
- tcpdump cheat sheet
- wireshark - Network protocol analyzer
Algorithms Used
- Boyer-Moore (bm) - String search algorithm
- Knuth-Morris-Pratt (kmp) - Pattern matching algorithm
Use Cases
- Ransomware Prevention: Block file extensions commonly used by ransomware
- Malware Protection: Prevent malicious file downloads via proxy
- Bot Blocking: Filter out malicious crawlers and bots
- Circumvention Control: Block proxy and VPN circumvention attempts
- P2P Blocking: Prevent BitTorrent and similar protocols
- Tor Blocking: Block Tor network access
- Samba Protection: Prevent ransomware from encrypting network shares
License
BlackShield is licensed under:- GPL-3.0
- CC BY-SA 4.0