Skip to main content

M3AAWG Tackles Emerging Security Issues with Industry Collaboration; Also Announces 2014 Leadership

San Francisco, April 22, 2014 Tackling security concerns with hosting and cloud storage, pervasive monitoring, identity management, and telephony, the Messaging, Malware and Mobile Anti-Abuse Working Group has announced the formation of four new collaborative special interest groups along with its organizational leadership for 2014.  The new SIGs provide a trusted venue for industry participation on critical issues while M3AAWG continues to support the ongoing work in its core security tracts.

Protecting end-users has become increasingly complex, requiring broad industry cooperation across multiple disciplines. The new M3AAWG Hosting SIG is also working with the i2Coalition and other industry partners to develop best practices.  The SIG will address issues with cloud storage security, identifying and removing illegitimate accounts, and protecting hosting servers against DDoS and other attacks.  The new M3AAWG Pervasive Monitoring SIG was formed in response to members’ concerns related to recent disclosures about extensive governmental monitoring of the Internet and how the consequent reaction by the technical community may impact, or even reduce, the ability to mitigate online abuse.

Earlier this year, the M3AAWG Voice and Telephony Abuse SIG hosted 90 technical experts, academic researchers, public policy advisors and representatives from government and law enforcement at a two-day workshop addressing robocalls and other voice abuse problems. A second VTA SIG workshop on June 18-19 in Montreal is also open to non-members, and European industry and government representatives will attend a briefing and cooperative data exchange at the M3AAWG 31st General Meeting in Brussels, Belgium, on June 9-12.

“Sharing timely information about attack vectors, vulnerabilities and proven security methods is crucial to protecting the Internet and providing end-users an accessible and safe online experience.  The collaborative work that will come out of these new SIGs will help fix urgent security issues and will augment the ongoing projects in our other M3AAWG committees to define the latest anti-abuse techniques,” said Chris Roosenraad, who is with Time Warner Cable and serving his third term as M3AAWG chairman.

2014 Leadership Look to Share Best Practices and Training

M3AAWG also announced the other 2014 Board officers serving with M3AAWG Chairman Roosenraad as M3AAWG co-vice chairmen Michael Adkins, Alex Bobotek of AT&T and Jerome Cudelou of Orange.  Sam Silberman of Constant Contact is treasurer and Jerry Upton continues as M3AAWG executive director.

The committees are supported in their work by M3AAWG Senior Technical Advisors, who are recognized industry experts with in depth knowledge in relevant fields.  The current advisors were all reappointed for 2014 and include Richard Clayton, Ph.D.; Dave Crocker; David Dagon, Ph.D.; John Levine, Ph.D.; April Lorenzen; and Joe St Sauver, Ph.D.

M3AAWG committees develop the organization’s best practices and other work that fight abuse and malware.  The 2014 committee chairs are:

  • Academic Committee Co-Chairs Manos Antonakakis, Ph.D., Georgia Tech; and M3AAWG advisor Joe St Sauver, Ph.D.
  • Awards Committee Co-Chairs Tami Forman, Return Path; and Neil Schwartzman, CAUCE
  • Brand SIG Co-Chairs Mike Hammer, AG Interactive; and Franck Martin, LinkedIn
  • Collaboration Committee Co-Chairs Christine Borgia, Return Path; Angela Knox, Cloudmark; and Sara Roper, CenturyLink
  • Hosting SIG Co-Chairs M3AAWG Chairman Emeritus Michael O’Reirdan, Comcast; and Schwartzman
  • Identity Management SIG Co-Chairs O’Reirdan and St Sauver
  • M3AAWG Open Round Tables co-chairs Melinda Plemel, Return Path; and Jordan Rosenwald, Comcast
  • Pervasive Monitoring SIG with co-chairs O'Reirdan and M3AAWG co-vice chairman Adkins
  • Program Committee Co-Chairs Kurt Andersen, LinkedIn; Dennis Dayman, Oracle/Eloqua; and Len Shneyder
  • Public Policy Committee Co-Chairs Frank Ackermann; Chris Boyer, AT&T; and Rudy Brioche, Comcast
  • Senders Committee Co-Chairs Andrew Barrett, iContact, a Vocus company; and Tara Natanson, Constant Contact
  • Technical Committee Co-Chairs Henry Stern, Farsight Security; and Jamie Tomasello, CloudFlare.  For specific work areas, Chris Barton, and Severin Walker, Comcast, are co-chairs for messaging; Paul Ferguson, Internet Identity; and Maxim Weinstein, Sophos, are co-chairs for malware; M3AAWG Co-Chairman Bobotek and Antti Tikkanen, F-Secure, are mobile co-chairs
  • Training Committee Co-Chairs Sam Masiello, Groupon; Vincent Schönau, Abusix; and Autum Tyr-Salvia, Marketo
  • Voice and Telephony Abuse SIG Co-Chairs Bobotek and Mustaque Ahamad, Ph.D., Georgia Tech

Beyond driving discussions on relevant issues, the committee chairs also help shape the organization’s three meetings each year.  The M3AAWG 31st General Meeting in Brussels will be a multi-track event with a full day of training.  Industry experts will lead over 30 sessions on mobile security, technical discussions on pervasive monitoring, international public policy and other anti-abuse areas.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) represents more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Linda Marcus, APR, 1+714-974-6356 (U.S. Pacific), LMarcus@astra.cc, Astra Communications

M3AAWG Board of Directors: AT&T (NYSE: T); CenturyLink (NYSE: CTL); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Constant Contact (NASDAQ: CTCT); Cox Communications; Damballa, Inc.; Facebook; Google; LinkedIn; Mailchimp; Orange (NYSE and Euronext: ORA); PayPal; Return Path; Time Warner Cable; Verizon Communications; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adobe Systems Inc.; AOL; BAE Systems Detica; Cablevision Systems Inc.; Campaign Monitor Pty.; Cisco Systems, Inc.; CloudFlare; Dynamic Network Services Inc.; iContact; Internet Initiative Japan (IIJ, NASDAQ: IIJI); Litmus; McAfee Inc.; Message Bus; Mimecast; Nominum, Inc.; Oracle/Eloqua; Proofpoint; Scality; Spamhaus; Sprint; Symantec and Twitter.

A complete member list is available at /about/roster.

 

M3AAWG Announces 2013 Leadership for Fighting Malware and Mobile Abuse

San Francisco, March 20, 2013 Emphasizing the need for more cooperative cybersecurity efforts across platforms, the Messaging, Malware and Mobile Anti-Abuse Working Group will continue with a diverse leadership structure for 2013.  Alex Bobotek of AT&T and Chris Roosenraad of Time Warner Cable will continue as M3AAWG Co-Chairmen with Michael O’Reirdan of Comcast continuing as a Board member and M3AAWG Chairman Emeritus.

Michael Adkins will remain as vice chairman with M3AAWG Executive Director Jerry Upton serving as the Board secretary. Anthony Purcell was also re-elected treasurer during the February 21 Board elections held at the M3AAWG 27th General Meeting in San Francisco. 

Last year M3AAWG expanded from its original mission of fighting spam to a broader charter that includes the urgent problems of confronting malware and fighting abuse on mobile platforms.  It works to protect end-users by sharing information across platforms, developing best practices and educating policy makers on relevant operational issues.

“Whether on a smartphone or a computer, malware can ravage users and cause extensive damage across networks.  The best way to safeguard end-users today is to cut through the operational silos that have developed in the industry and leverage our cybersecurity knowledge across platforms and among diverse areas of expertise, ” Roosenraad said.

Both Bobotek and Roosenraad served as M3AAWG co-chairmen in 2012 and as co-vice chairmen for the two previous years, providing continuity as the organization evolves with the changing industry.  Bobotek, AT&T Lead of Messaging Anti-Abuse Architecture and Strategy, will also continue as a co-chair of the Technical Committee where he has helped develop programs to fight mobile abuse for several years.  Roosenraad, Time Warner Cable Director of Systems Engineering, previously was a co-chair of the Technical Committee and of the Program Committee.

M3AAWG Senior Technical Advisors Richard Clayton, Ph.D.; Dave Crocker; David Dagon, Ph.D.; John Levine, Ph.D.; April Lorenzen; and Joe St Sauver, Ph.D. were reappointed. The advisors are experts with in depth knowledge in specific areas and assist the committees in their work.  The committees are responsible for developing best practices and other work to fight online abuse. 

The committee chairs appointed by the Board for 2013 are:

  • Academic Committee, which was recently formed to bring the latest research to M3AAWG members, Co-Chairs Manos Antonakakis, Ph.D., of Damballa and Joe St Sauver
  • Awards Committee co-chaired by Purcell and Neil Schwartzman, CAUCE
  • Brand SIG Co-Chairs Mike Hammer, AG Interactive; and Franck Martin, LinkedIn
  • Collaboration Committee Co-Chairs Christine Borgia, Return Path; Angela Knox, Cloudmark; and Sara Roper, CenturyLink
  • M3AAWG meeting Open Round Tables session chair Jordan Rosenwald, Comcast
  • Program Committee Co-Chairs Dennis Dayman, Eloqua; Len Shneyder, Message Bus; and Jamie Tomasello, CloudFlare
  • Public Policy Committee Co-Chairs Frank Ackermann, eco–Association of the German Internet Industry; Chris Boyer, AT&T; and Rudy Brioche, Comcast
  • Senders SIG Co-Chairs Andrew Barrett of iContact and Tara Natanson of Constant Contact
  • Technical Committee Co-Chairs Alex Bobotek; Chris Barton, Cloudmark; Paul Ferguson, Internet Identity; and Matthew Steele, Symantec
  • Training Committee Co-Chairs Kurt Andersen, LinkedIn; and Sam Masiello, CAUCE

The committees also develop educational and information-sharing sessions on emerging issues for M3AAWG meetings held three times a year.  The organization’s annual European meeting will be held in Vienna, Austria, June 3-6, and will feature training courses and three multi-track days of speakers, confidential industry dialogue, public policy reports and working committee sessions.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) represents more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Linda Marcus, APR, 1+714-974-6356 (U.S. Pacific), LMarcus@astra.cc, Astra Communications

M3AAWG Board of Directors: AT&T (NYSE: T); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Constant Contact (NASDAQ: CTCT); Cox Communications; Damballa; Eloqua; Facebook; France Telecom (NYSE and Euronext: FTE); Google; PayPal; Return Path; Symantec; Time Warner Cable; Verizon Communications; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adaptive Mobile Security LTD; Adobe Systems Inc.; AOL; BAE Systems Detica; Cisco Systems, Inc.; CloudFare; Dynamic Network Services Inc.; Email Sender and Provider Coalition; Experian CheetahMail; Genius; iContact; Internet Initiative Japan (IIJ NASDAQ: IIJI); Mailchimp; McAfee Inc.; Message Bus; Mimecast; Nominum, Inc.; Proofpoint; Scality; Spamhaus; Sprint; and Twitter.

A complete member list is available at /about/roster

M3AAWG San Francisco Meeting Addresses Latest Messaging Security Ranging from Mobile Malware to DDoS Attacks

San Francisco, Jan. 30, 2013 – With the variety of devices in use today and the pervasive connectivity available to users, malware could easily get the upper hand on many networks without corrective measures.  The Feb. 19-21 M3AAWG 27th General Meeting in San Francisco will focus on helping the industry develop the necessary strategies to protect end-users from the latest messaging abuses, whatever the abuse vector or device that is targeted. 

The Messaging, Malware and Mobile Anti-Abuse Working Group meeting will offer six sessions focusing specifically on emerging mobile malware and security issues along with presentations on computer bot research, international cybersecurity efforts, social media issues and other topics.  There will also be three tracks of security-related training on Feb. 18.

Recognizing the need for cross-industry cooperation within the messaging industry, M3AAWG works to foster an environment where experts from all areas of cybersecurity can share their experience and learn from each other. Sessions at the meeting will explore the challenge of protecting online advertising, present a DNS Changer Working Group study, offer practical spam trap tips, and provide an open dialogue between email service providers that send third party messages and ISPs, along with other topics. Among the mobile sessions, noted industry experts will discuss current Android viruses, abuse of mobile payment systems, and the evolution of mobile malware. 

“The malware on an end-user’s system might have been delivered through email, an SMS with a link to a drive-by website, a tainted mobile app or another vector.  But however it got there, it can be dangerous and costly to the user, and it can have devastating and far-reaching effects on other networks and users.  To effectively tackle malware, we need to share information, both across areas of expertise and across international borders,” said Alex Bobotek, M3AAWG Co-Chairman.

AllThingsD.com Co-Executive Editor Kara Swisher will keynote the meeting, sharing her perspective on how the Internet has changed since she began covering technology for both The Washington Post and The Wall Street Journal and where she sees the industry going in the near future.  The Electronic Frontier Foundation’s International Freedom of Expression Coordinator Eva Galprin will also offer a keynote presentation on the status of Syrian malware.

Emphasizing the international aspect of fighting abuse, Dr. Victoria Baines, strategic advisor on cybercrime at the European Police Office (EUROPOL) in The Hague, will elaborate on Project 2020, a range of activities to enhance online security including common threat reporting, strategic foresight exercises, policy guidance and capacity building. In another session, a panel will discuss the state of spam and industry outreach efforts to share best practices in the BRIC countries (Brazil, Russia, India and China).

The Monday training sessions (/activities/training) will cover machine learning, analysis of anti-abuse data, encryption, and an end-to-end process for sharing data within the security community.  Speakers at the meeting will also address methods to defend against DDoS attacks, the social media spam marketplace, URL redirection and issues of online bullying, along with working sessions to develop best practices.

The San Francisco meeting is the only Silicon Valley event M3AAWG will host this year.  Its European meeting will be in Vienna, Austria in June and its October East Coast meeting in Montreal, Canada.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) represents more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.

#  #  #

Media Contact: Linda Marcus, APR, 1+714-974-6356 (U.S. Pacific), LMarcus@astra.cc, Astra Communications

M3AAWG Board of Directors: AT&T (NYSE: T); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Constant Contact (NASDAQ: CTCT); Cox Communications; Damballa, Inc.; Eloqua; Facebook; France Telecom (NYSE and Euronext: FTE); Google; Message Bus; PayPal; Return Path; Symantec; Time Warner Cable; Verizon Communications; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adaptive Mobile Security LTD; Adobe Systems Inc.; AOL; BAE Systems Detica; Cisco Systems, Inc.; Dynamic Network Services Inc.; Email Sender and Provider Coalition; Genius; iContact; Internet Initiative Japan (IIJ NASDAQ: IIJI); Mailchimp; McAfee Inc.; Message Systems; Mimecast; Nominum, Inc.; Proofpoint; Scality; Spamhaus; Sprint; and Twitter.

A complete member list is available at /about/roster.

New Online and Mobile Best Practices Clarify Business and Governmental Security Tactics

Baltimore, Oct. 24, 2012 – A cooperative international report available today outlines Internet and mobile best practices aimed at curtailing malware, phishing, spyware, bots and other Internet threats, and provides a thorough review of current and emerging threats.  “Best Practices to Address Online and Mobile Threats” is a comprehensive assessment of Internet security as it stands today and explains in non-technical language the proactive steps that can help mitigate risks, according to the report’s two major contributors, the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) and the London Action Plan (LAP).

The report is also one of the first global efforts to encourage governments to deploy best practices, which are more often associated with businesses.  It focuses on four major areas of concern: malware and botnets, social engineering and phishing, IP and DNS exploits, and mobile threats.  To encourage government participation, it has been presented to the 34-member country OECD (Organisation for Economic Cooperation and Development) for review.

Best Practices to Address Online and Mobile Threats” draws on the tactics that have proven effective over the past decade to reduce online risks, then augments these with forward-thinking recommendations for emerging vulnerabilities, such as mobile text spam and Web abuse.  The comprehensive report is available on the websites of several organizations including at M3AAWG_LAP_Best_Practices_to_Address_Online_and_Mobile_Threats.pdf, http://www.londonactionplan.com/files/legacy/reports/Best_Practices_to_Address_Online_and_Mobile_Threats_(Oct_2012).pdf and http://www.cauce.org/2012/10/best-practices-report.html

“As a globally cooperative effort, the report brought together an unprecedented team of experts who outlined safe computing tactics in uncomplicated, accessible language for end-users, large and small businesses, and governments.  This is also one of the first efforts to update industry recommendations recognizing that public agencies are important online enterprises, and just as companies need to implement best practices, so do governments,” Alex Bobotek, M3AAWG co-chairman said. 

The international community collaboratively stepped up to generate the report in a public-private partnership led by Andre Leduc, manager, national anti-spam coordinating body at the Department of Industry Canada.  Industry experts from M3AAWG, LAP and other organizations, such as CAUCE (Coalition Against Unsolicited Commercial Email), contributed to it.

Online threats are evolving as Internet and mobile technologies play a more vital role in many business models, attracting cybercriminals who target users on popular platforms such as laptops, tablets, smartphones and other handheld devices.  As the Internet economy grows, implementing the best practices detailed in the report will help reduce illegal activities such as spam, phishing, malware and spyware distribution, botnet deployment, the redirection of Internet traffic to malicious websites and denial of service attacks.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) represents more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is an open forum driven by market needs and supported by major network operators and messaging providers.

About the London Action Plan (LAP)

The LAP is a 45-member organization of law enforcement agencies and industry participants focused on fighting spam and other online threats. The LAP conducts regular teleconferences and an annual meeting.  Its most recent meeting, held in London, England, in October 2012 included participants from Europe, Asia, North America and Europe.

Media Contact: Linda Marcus, APR, +1-714-974-6356, LMarcus@astra.cc, Astra Communications

M3AAWG Board of Directors: AT&T (NYSE: T); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Constant Contact (NASDAQ: CTCT); Cox Communications; Damballa, Inc.; Eloqua; Facebook; France Telecom (NYSE and Euronext: FTE); La Caixa; Message Bus; PayPal; Return Path; Time Warner Cable; Verizon Communications; and Yahoo! Inc.

M3AAWG Full Members: 1&1 Internet AG; Adaptive Mobile Security LTD; Adobe Systems Inc.; AOL; BAE Systems Detica; Cisco Systems, Inc.; Dynamic Network Services Inc.; Email Sender and Provider Coalition; Experian CheetahMail; Genius; iContact; Internet Initiative Japan (IIJ NASDAQ: IIJI); McAfee Inc.; Message Systems; Mimecast; Nominum, Inc., Proofpoint; Scality; Spamhaus; Sprint; Symantec; Trend Micro, Inc.; and Twitter.

A complete member list is available at /about/roster.