Skip to main content

A client for use with the SCRAM black hole routing software.

Project description

scram-client

This is the client python script that needs to be installed on a system in order to inject blackhole router blocks w/ SCRAM.

Dependencies

The scram-client requires a locally running Redis server if you intend to use the queue mode. There are also several python module dependencies (see below).

Installation

The scram-client is generally installed into a python3 virtual environment via:

(scram_client_venv)$ pip install git+https://github.com/esnet-security/scram-client.git#egg=scram_client

or via ansible, similar to:

  - name: Install Shared Pip Dependencies
    pip:
      name: "{{ item }}"
      virtualenv: "{{ scram_client_venv }}"
    loop:
      - "git+https://github.com/esnet-security/scram-client.git#egg=scram_client"
      - "requests"
      - "prometheus-client"
      - "walrus"
    become: true
    become_user: "{{ scram_client_user }}"

If you will be using the queue manager functionality as well, a template systemd file would look as follows:

[Unit]
Description=scram queue management
After=network.target

[Service]
User={{ scram_client_user }}
EnvironmentFile=/etc/sysconfig/scram-client.conf
ExecStart={{ scram_client_venv }}/bin/scram-client run_queue
Restart=always
RestartSec=10s

[Install]
WantedBy=multi-user.target

Configuration

The scram client requires a few variables to be set either in the environment or in a configuration file at /etc/sysconfig/scram-client.conf.

[SCRAM]
SCRAM_HOST=scram-server.my.network
SCRAM_UUID=012a3f45-6789-1234-ab56-7890b12c345d
SCRAM_PROMETHEUS_PORT=9115
SCRAM_LOGLEVEL=INFO

Client Initialization

The UUID can either be assigned by the SCRAM administrator or a client can register itself using the API. A registered client still needs to have the SCRAM administrator authorize the client.

Auto-registration:

$ source scram_client_venv/bin/activate
(scram_client_venv)$ scram-client register [server hostname]

Modes of Operation

Block

The simplest mode is 'block.' As the name implies this allows you to send a block directly to SCRAM without any queue'ing taking place. It's also a good way to make sure your client is configured and working properly.

$ source scram_client_venv/bin/activate
(scram_client_venv)$ cat testblock
10.1.1.4
my_note
my_msg
my_sub
600
(scram_client_venv)$ scram_client block < testblock
INFO:root:Successfully blocked 10.1.1.4 for my_note: my_msg my_sub.

Queue

Queue mode works in much the same way from the user perspective, but instead of directly blocking the IP, the block request is added to a queue via Redis.

Run_queue

Run_queue mode is generally managed via systemd and simply reads the Redis queue and then performs the 'block' mode operation.

Register

The register comand simply generates a new UUID and sends it to the SCRAM server to initliaze a new client. The SCRAM admin then needs to authorize the client as well as allow whichever actiontypes for that client in the SCRAM admin webUI.

Sample Architecture Diagram

We use zeek here as an example service that uses the scram-client:

SCRAM Client Example

Project details


Release history Release notifications | RSS feed

This version

0.5

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

scram_client-0.5.tar.gz (7.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

scram_client-0.5-py3-none-any.whl (7.7 kB view details)

Uploaded Python 3

File details

Details for the file scram_client-0.5.tar.gz.

File metadata

  • Download URL: scram_client-0.5.tar.gz
  • Upload date:
  • Size: 7.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.1

File hashes

Hashes for scram_client-0.5.tar.gz
Algorithm Hash digest
SHA256 8e7357927dc2f7af0e9add9a3c56c049eabc37d9ae3dce49f785982c867e8437
MD5 9123c59e1fcad040f9f96b057355bfab
BLAKE2b-256 75848d4162121bfe1ee023da65a9af9c17e4813603531c2d6381c7c7e4ffdb56

See more details on using hashes here.

File details

Details for the file scram_client-0.5-py3-none-any.whl.

File metadata

  • Download URL: scram_client-0.5-py3-none-any.whl
  • Upload date:
  • Size: 7.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/4.0.2 CPython/3.9.1

File hashes

Hashes for scram_client-0.5-py3-none-any.whl
Algorithm Hash digest
SHA256 56aabc9d2c5b8d3f94d1092548a603fd40cac91ecc15a0533b9b8fe4dcc781dc
MD5 155e661aeef99da6ead2f47d0630a7b3
BLAKE2b-256 c73b65b64449632f7eaea6fc625b01b5c79ad0bff9e3741de8d56b0cba8ea4ae

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page