It sounds like what you really want is to go to the firewall app and set the default action at the bottom to "block" rather than "pass". Then (before applying) add a rule to pass traffic for ports 53, 80, and 443 (and maybe also 993, 995, and 587 for certain e-mail hosts). That's will (over)kill the worst of your bandwidth abuses. All that's left is anyone desperate enough to configure a bittorrent client to use port 80 or 443. One other consideration is if you have a SIP-based phone service using your internet connection. You'll need a few ports open for that, as well.