Skip to main content

First Japan Anti-Abuse Working Group General Meeting Shares M3AAWG Work with Emphasis on Regional Issues

San Francisco, Nov. 1, 2018 – Strengthening Asian efforts to protect the internet and online users, the First General Meeting of the Japan Anti-Abuse Working Group will be held Nov. 8 in Tokyo with security and operational professionals from messaging service providers, cloud hosting services, ISPs and other infrastructure organizations. The meeting is an independent regional offshoot of the global Messaging, Malware and Mobile Anti-Abuse Working Group and will focus on cybersecurity issues related to Japan’s unique challenges.

“JPAAWG was formed as a place where local industry professionals can collaborate and share information to better protect our internet users. Our goal is to disseminate the proven industry best practices developed by M3AAWG and explore how these apply to Japan then bring back to M3AAWG information on the specific abuse in our region. We also are encouraging other Asian countries to participate in the global anti-abuse community through our regional organization,” said the JPAAWG Secretariat Shuji Sakuraba, who is also the application service department general manager at the Internet Initiative Japan (IIJ).

The one-day meeting will cover topics such as DMARC, a widely-used email authentication technology; identity and data protection; how to protect against spam; and the global threat outlook. M3AAWG Chairman of the Board Severin Walker will open the meeting along with Sakuraba and M3AAWG Vice Chairperson Janet Jones will be the keynote, with other M3AAWG members also presenting.  The meeting is part of the 18th Anti-Spam Conference being held at the Akasaka Intercity Conference Center (AIR).

Walker said, “Regional organizations like JPAAWG are important because online threats tend to flow from country to country, so there is both a global and local aspect to protecting end-users. In M3AAWG, we bring together professionals from around the world to share what has worked for them in fighting cybercrime and online abuse, then we distill this information into best practices and other anti-abuse work. The local professionals in the regional organizations decide how best to apply these processes to their ecosystem and also raise new issues to be addressed by the M3AAWG community.”

IIJ has been an active member of M3AAWG since it was founded in 2004. They have taken the lead and collaborated with TwoFive and several other local businesses to develop JPAAWG.

M3AAWG holds three global meetings each year, two in North America and one in Europe, with about 500 cybersecurity professionals from 30 countries attending.  M3AAWG also offers support to other regional organizations starting local anti-abuse groups, for example, in the Latin America and Caribbean NIC region. The 45th M3AAWG General Meeting will be San Francisco, Feb. 18-21, 2019.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than two billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: pr@m3aawg.org

M3AAWG Board of Directors and Sponsors: Adobe Systems Inc.; AT&T; Comcast; Endurance International Group; Facebook; Google, Inc.; LinkedIn; Marketo, Inc.; Microsoft Corp.; Oath (Yahoo/AOL); Orange; Proofpoint; Rackspace; Return Path, Inc.; SendGrid, Inc.; Vade Secure; Valimail; and VeriSign, Inc.

M3AAWG Full Members: 1&1 Internet SE; Agora, Inc.; Akamai Technologies; Campaign Monitor; Cisco Systems, Inc.; CloudFlare, Inc.; Cyren; dotmailer; eDataSource Inc; ExactTarget, Inc.; IBM; iContact; Internet Initiative Japan (IIJ); Liberty Global; Listrak; Litmus; McAfee; Mimecast; Oracle Marketing Cloud; OVH; PayPal; Spamhaus; Splio; Symantec; USAA; and Valimail.

A complete member list is available at /about/roster.

 

 

M3AAWG Expert Advisors

M3AAWG Expert Advisors are highly respected experts chosen for their skills and industry proficiency.  The M3AAWG Expert Advisors provide industry-leading insight, perspectives and content for our members. Expert Advisors contribute to the success of M3AAWG by their work in our Priority Committees, Special Interest Groups (SIG) and on our Initiatives.  

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) Privacy Notice

May 7, 2019 - Version 1.2 - Download the M3AAWG Privacy Notice

We know that your privacy is important. At M3AAWG we are committed to helping you understand how we manage and protect it. This Privacy Notice is provided to inform you of our privacy policies, data collection and usage practices, and our communications with Members and Non-members.

Taking on Calendar Spam, Scheduling Developers Organization CalConnect Collaborates with Messaging Anti-Abuse M3AAWG

McKinleyville, CA and San Francisco, April 5, 2018 – Recognizing that calendar spam is a growing exploitation channel, CalConnect and the global anti-abuse association M3AAWG have joined forces to develop new methods to protect end-users from unsolicited and malicious event notices.  The new liaison between the scheduling developers’ organization and the Messaging, Malware and Mobile Anti-Abuse Working Group will accelerate industry efforts to develop techniques that block invites to fake events and other malicious notices on popular calendaring platforms.

Calendar spam is a new form of abuse that takes advantage of the application layer across multiple technologies, including scheduling, calendaring and messaging systems. For example, users have received fraudulent emails impersonating well-known brands that include calendar invites to special “discount” events.  As is the case with email spam, calendar spam can be used for malicious purposes such as phishing or to deliver malware payloads.

CalConnect (The Calendaring and Scheduling Consortium) also has established a new technical committee, TC CALSPAM, to better protect users from calendar system abuse. The committee aims to understand the current and potential use of calendar systems as a vector for delivering undesired information and will provide current information and guidelines on the topic to CalConnect and M3AAWG participants.

"Calendaring is an intimate part of everyone’s lives. Calendar spam is particularly unsettling because the abuse directly pops up on a person’s calendar.  It’s personally disruptive and especially disturbing," said Thomas Schäfer, 1&1’s Head of Technical Site Management who chairs TC CALSPAM.

Differs from Other Abuse Schemes

CalConnect and M3AAWG will develop the measures and best practices for developers and system operators to ensure legitimate usage of their platforms.  The collaborative effort is important because calendar spam is unique as an abuse vector in a number of ways:

  • Calendar spam, unlike email, can be placed chronologically anywhere in a calendar – in the past or the future, not just the present – making it difficult to detect at the time of delivery.
  • Spam meeting invitations can be automatically added to calendars without the users’ consent with notifications sent to all their devices. These invitations are not only difficult to find but, in some cases, there is no way for the user to remove these events short of deleting the entire calendar.
  • Calendar events and meeting invitations do not yet carry the rich provenance, i.e., the detailed header information that is included in email, making it difficult to ascertain where and when events originated and where they were delivered.
  • Calendar events often contain notifications or alarms that are propagated across a user’s many desktop and mobile calendaring clients, exacerbating the problem.

M3AAWG Executive Director Jerry Upton said, “Calendar spam has shown itself to be a new but rapidly maturing vector for spammers.  As we’ve seen in addressing other abuse issues in M3AAWG, cross-domain problems like this require input from experts in multiple disciplines and collaborating with CalConnect and their subject matter is the most direct route to combatting this evolving threat."

Call for Industry Participation

The reciprocal membership agreement between the two organizations became effective in February and allows the calendaring and scheduling developers, vendors and service providers in CalConnect and the messaging and email authentication experts in M3AAWG to share information and work.  CalConnect members participated in the M3AAWG 42nd General Meeting in San Francisco in February, kicking off the joint work on applicable anti-abuse methodologies.  The 43rd M3AAWG General Meeting will be held June 4-7 in Munich, Germany.

CalConnect President Rutger Geelen said, “We recognize that calendar spam is a real threat and a growing problem. First and foremost, we endeavor to protect users against such abuse. Since event and meeting invitations are often delivered via email, it makes sense to collaborate with the messaging identity and authentication experts at M3AAWG in our effort to return full control of collaboration and communications to the end users themselves."

Organizations interested in joining the CalConnect calendar spam committee should contact CalConnect Executive Director Dave Thewlis at dave.thewlis@calconnect.org or CalConnect Director of External Relations Ronald Tse at ronald.tse@calconnect.org

About The Calendaring and Scheduling Consortium (CalConnect)

CalConnect, The Calendaring and Scheduling Consortium, CalConnect, is a not-for-profit organization advancing the state of interoperable calendaring, scheduling and digital contacts. Founded in 2004 as a partnership between vendors and users of calendaring and scheduling tools and technologies, its membership includes some of the world’s largest software companies as well as small startups. Virtually every important calendaring-related standard since 2004 has been authored, edited, and/or co-edited by members of a CalConnect Technical Committee. http://www.calconnect.org.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy, and works to educate global policy makers on the technical and operational issues related to online abuse and messaging.

#  #  #

Media Contacts:

Ronald Tse, Director, External Relations, ronald.tse@calconnect.org, CalConnect (The Calendaring and Scheduling Consortium), https://www.calconnect.org

PR@m3aawg.org, M3AAWG (Messaging, Malware and Mobile Anti-Abuse Working Group), https://www.m3aawg.org

M3AAWG Issues New Papers Explaining Password Security, Multifactor Authentication, Encryption Use and DDoS Safeguards; Announces 2017 Leadership and Committee Chairs

San Francisco, April 4, 2017 – Addressing current threats such as DDoS attacks and Internet of Things security, the Messaging, Malware and Mobile Anti-Abuse Working Group has released five new best practices papers and created new special interest groups to develop cybersecurity approaches that will help protect end-users. The organization also announced its 2017 leadership and committee chairs who are responsible for supporting the group’s ongoing collaborative efforts and identifying new areas of online vulnerability.

The new best practices papers outline recommended processes to help companies and service providers better safeguard their networks and are based on the experience of anti-abuse experts in computer security, business, public policy and academia.  The papers are:

M3AAWG currently has 42 papers available on its website under the For the Industry tab in its Best Practices section at /published-documents.  These best practices and tutorials address both emerging and ongoing anti-abuse challenges, such as methods to counter pervasive monitoring, abuse desk processes, anti-phishing and spam techniques, recommended senders best practices and other relevant topics.

Special Interest Groups Focus on Global Issues

M3AAWG also formed a new Internet of Things SIG to coordinate members’ efforts in resolving abuse issues from compromised IoT devices.  The new special interest group will develop reputation guidelines and processes for the supply chain while promoting consumer security awareness and working with manufacturers to build better security into devices.

The M3AAWG DDoS SIG is focused on helping ISPs, hosting companies and third-party DDoS security service providers understand existing and emerging Distributed Denial of Service attack types. It is developing additional papers that will explain prevention methods, monitoring and mitigation architectures, and business strategies.

2017 Leadership Takes the Helm

Along with finalizing the papers during the M3AAWG 39th General Meeting in San Francisco last month, Severin Walker, senior manager, Comcast Anti-Abuse Engineering, was elected the new Chairman of the M3AAWG Board. He has contributed to the organization over the past five years as a Board member and a chair of the M3AAWG Technical Committee. 

Also elected at the February 23 Board meeting were vice chairpersons Janet Jones, senior security program manager in Microsoft’s Trustworthy Computing Security organization; Len Shneyder, SendGrid, Inc. vice president of industry relations; and Matthew Stith, Rackspace anti-abuse specialist. Sam Silberman, Endurance International Group director of standards and industry relations, will serve his fourth term as treasurer and Jerry Upton continues as executive director.

Most of the work and best practices in M3AAWG are generated through dialogue among industry professionals in topical committees.  The committees meet on regularly scheduled conference calls and during the three M3AAWG working meetings each year to develop the anti-abuse recommendations and other projects.

“M3AAWG provides a critical space where hundreds of subject matter experts from across the spectrum can collaborate in a trusted and vetted environment and, because of this, our work is important for the long-term security of the internet. M3AAWG committees provide the structure – they are the super-highways – that ensure these discussions are meaningful and address the critical issues. So eventually, the volunteer M3AAWG committee chairs are the ones who keep the energy and our work flowing,” Walker said in announcing the 2017 committee chairs:

  • Abuse Desk Co-Chairs Charles Helstein, PayPal; Tobias Knecht, Abusix, Inc.; and Justin Paine, Cloudfare
  • Academic Committee Co-Chairs Dr. Manos Antonakakis, Georgia Tech, and Carel, Spamhaus
  • Anti-Phishing SIG Co-Chairs Carlos Alvarez, ICANN, and Chelsea Maldonado, Mailchimp
  • Awards Committee Co-Chairs Christine Borgia, Return Path, and Neil Schwartzman, CAUCE
  • Brand SIG Co-Chairs Ryan Boyd, Groupon, and Mike Hammer, AG Interactive
  • Collaboration Committee Co-Chairs Stephen Ford, Adobe Systems Inc.; Sven Krohlas, 1 & 1 Internet SE; and Mary Youngblood
  • DDoS SIG Co-Chairs Mike Glenn, Cable Television Laboratories, Inc., and Glen Pirrotta, Comcast
  • Hosting Committee Co-Chairs Matthew Stith, Rackspace, and Justin Lane, Endurance International Group
  • Information Sharing SIG Co-Chairs Chris Boyer, AT&T, and Doug Pearson, REN-ISAC
  • Internet of Things SIG Co-Chairs M3AAWG Senior Technical Advisor Michael O’Reirdan and Chris Roosenraad, NeuStar
  • M3AAWG Guides Co-Chairs Alyssa Nahatis, Adobe Systems, Inc., and M3AAWG Privacy Advisor William Wilson, Breckenhill Inc.
  • M3AAWG meeting Open Round Tables Co-Chairs Melinda Plemel, Proofpoint, and Vincent Schonau, Abusix
  • Pervasive Monitoring SIG Co-Chairs Janet Jones, Microsoft, and Alex Brotman, Comcast
  • Program Committee Co-Chairs Kurt Andersen, LinkedIn; Dennis Dayman, Return Path; and Len Shneyder, SendGrid, Inc.
  • Public Policy Committee Co-Chairs Frank Ackerman, M3AAWG Public Policy Advisor; Chris Boyer, AT&T; and Chris Roosenraad, NeuStar
  • Senders Committee Co-Chairs Andrew Barrett, Adobe Systems, Inc., and Tara Natanson, Endurance International Group
  • Technical Committee Chair Severin Walker, Comcast.  The Technical Committee area co-chairs are:
  • Messaging - Peter Goldstein, ValiMail, and James Hoddinott, Cloudmark, Inc.
  • Malware - Jeremy Demar, Vigilant By Deloitte, and Loucif Kharouni, Deloitte
  • Training Committee Co-Chairs Christine Borgia, Return Path; Kurt Diver, SendGrid, Inc.; Annalivia Ford, IBM; and Udeme Ukutt, Splio
  • Voice and Telephony Abuse SIG Co-Chairs Alex Bobotek, AT&T, and Dr. Mustaque Ahamad, Georgia Tech
  • Women in Messaging Abuse/Diversity and Inclusion Chair Janet Jones, Microsoft

Additionally, M3AAWG Senior Technical Advisor John Levine, founder of Taughannock Networks, was appointed M3AAWG liaison to ICANN.  Jesse Sowell continues as a special M3AAWG representative to LACNIC, the Latin America and Caribbean Network Information Center, and is helping to develop joint anti-abuse work with that organization.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Pr@m3aawg.org

M3AAWG Board of Directors: AT&T (NYSE: T); CenturyLink (NYSE: CTL); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); dotmailer; Endurance International Group; Facebook; Google; LinkedIn; Mailchimp; Microsoft Corp.; Orange (NYSE and Euronext: ORA); Rackspace; Return Path; SendGrid, Inc.; Vade Secure; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adobe Systems Inc.; Agora, Inc.; AOL; Campaign Monitor Pty.; Cisco Systems, Inc.; CloudFlare; Dyn; Exact Target, Inc.; IBM; iContact; Intel Security; Internet Initiative Japan (IIJ, NASDAQ: IIJI); Liberty Global; Listrak; Litmus; MAPP Digital; Mimecast; Nominum, Inc.; Oracle Marketing Cloud; OVH; PayPal; Proofpoint; Spamhaus; Sparkpost; Sprint; Symantec; and USAA.

A complete member list is available at /about/roster.