Welcome Guest. | Log In | Register | Membership Benefits

M3AAWG to Aggregate First ISP Bot Stats in Support of FCC Cybersecurity Efforts

M3 Anti-Abuse Working Group will aggregate bot data from ISPs

Feb 22, 2012 | 06:24 PM | 


San Francisco, Feb. 21, 2012 – The first program to report the number of bots logged by ISPs and network operators is being organized by the Messaging Anti-Abuse Working Group (M3AAWG) as part of a voluntary joint industry-government council under the U.S. Federal Communications Commission. The M3AAWG bot metrics report will include the only data aggregated directly from network operators and will be released later this year, according to Michael O’Reirdan, M3AAWG Chairman. The project is being developed in conjunction with the CSRIC Botnet Remediation Working Group 7, also chaired by O’Reirdan, as part of the FCC’s private industry-government cooperative to enhance online security. FCC Chairman Julius Genachowski will outline the work of the Communications Security, Reliability and Interoperability Council (CSRIC) in a speech on cybersecurity Feb. 22 at the Bipartisan Policy Center in Washington, D.C. A bot is malicious code or a virus downloaded to end-users’ computers without their knowledge. Bots on individual computers are strung together into covert networks, called “botnets,” and controlled by cybercriminals for illicit purposes, such as stealing personal identity information, sending spam, launching website attacks and other fraudulent activities. The new CSRIC-requested report will measure the number of bot-infected users each quarter and participation is voluntary. The data will be reported only as a total calculation and the contributing operators will not be identified, according to O’Reirdan. Network operators can participate by contacting M3AAWG through the organization’s website at www.M3AAWG.org/contact. M3AAWG has issued a similar quarterly spam metrics report since 2007 with data on the volume of abusive email identified by network operators. That report has consistently shown that mailbox providers stop almost 90 percent of spam before it reaches end-users’ inboxes. The CSRIC Working Group 7, which includes numerous M3AAWG member companies, is developing bot remediation practices outlining how ISPs should remove malware from end-users computers and the metrics to measure the industry’s progress in cleaning up the Internet. O’Reirdan has been actively directing M3AAWG efforts to aggressively tackle malware and was appointed to chair the related FCC CSRIC working group last year. The Messaging Anti-Abuse Working Group recently changed its name to M3AAWG – or M3 for Messaging, Malware and Mobile – because it wants to encourage the cooperation among experts in these areas that is necessary to better protect end-users. About the Messaging Anti-Abuse Working Group (MAAWG) The Messaging Anti-Abuse Working Group (M3AAWG) is where the messaging industry comes together to work against spam, malware, denial-of-service attacks and other online exploitation. M3AAWG (www.M3AAWG.org) – or M3 for Messaging, Malware and Mobile – represents more than one billion mailboxes from some of the largest network operators worldwide. It is the only organization addressing messaging abuse by systematically engaging all aspects of the problem, including technology, industry collaboration and public policy. M3AAWG leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services, including mobile. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is an open forum driven by market needs and supported by major network operators and messaging providers. # # # Media Contact: Linda Marcus, APR, 1-714-974-6356, LMarcus@astra.cc, Astra Communications MAAWG Board of Directors: AOL; AT&T (NYSE: T); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); Constant Contact (CTCT); Cox Communications; Damballa, Inc.; Eloqua; Facebook; France Telecom (NYSE and Euronext: FTE); La Caixa; Message Bus; PayPal; Return Path; Time Warner Cable; Verizon Communications; and Yahoo! Inc. MAAWG Full Members: 1&1 Internet AG; Adaptive Mobile Security LTD; BAE Systems Detica; Cisco Systems, Inc.; Dynamic Network Services Inc.; Email Sender and Provider Coalition; Experian CheetahMail; Genius.com; iContact; Internet Initiative Japan, (IIJ NASDAQ: IIJI); MailUp; McAfee Inc.; Message Systems; Mimecast; MXTools; Proofpoint (everyone.net); Scality; Spamhaus; Sprint; Symantec; and Trend Micro, Inc. A complete member list is available at http://www.M3AAWG.org/about/roster.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Insider Threat Reports

report How to Prevent an Illicit Data Dump
There are no silver bullets when it comes to protecting company and customer data from loss or theft, but there are technological and procedural systems that will go a long way toward preventing a WikiLeaks-like data dump. Here are some tips and tricks to help protect your organization's most sensitive information.

report Email and Data Loss
Email encryption, rights management, email gateways, and full-on data loss prevention systems can keep corporate data secure. Here's a look at the pros and cons of each, to help you determine what?s best for your business.

report An Insider Threat Reality check
Heightened concern that users could inadvertently expose or leak -- or purposely steal -- an organization's sensitive data has spurred debate over the proper technology and training to protect the crown jewels. In this special retrospective of recent news coverage, Dark Reading takes a look at how organizations are handling the threat -- and what users are really up to.

Other reports from the Insider Threat Tech Center:

Related Content

Protection from Insider Threats
Preventing data misuse by trusted users is the most difficult information protection challenge. Insiders already have full authorization to the data, making traditional IT secure methods in effective. Learn about a more powerful security approach and proven strategies to prevent insider misuse.

Strategies for Protecting Intellectual Property
A company's intellectual property (IP) represents a significant portion of assets and a critical component of competitive differentiation, but the potential value of any IP is directly linked to its limit of acceptable use. Learn how you can put your IP to work within collaborative environments without undue risk and maximize competitive advantages.

Protecting Against WikiLeaks Type Events and the Insider Threat
The sensitive information supplied to WikiLeaks and other social justice websites comes from trusted insiders. Get the answers to the open gaps left in the WikiLeaks story and learn how you can prevent insider threats that are just as detrimental in your organization.

Insider Threat: An Inside Look at a Fortune 100 Company's Prevention Program
The ways and means by which a privileged user can successfully steal proprietary data today is staggering. One venerable company that suffered a devastating incident decided to do something about it. Find out how it built one of the most productive insider threat prevention programs in the Fortune 100.

Protection of Intellectual Property and Trade Secrets across a Global Enterprise
As a designer and manufacturer of industrial technology, this Fortune 50 company knew that securing their intellectual property (IP) and trade secret data was essential. It created a program to identify risks to their IP and trade secrets and soon caught a privileged user attempting to compromise IP. Download this case study to see a real example of intellectual property protection at work.




Featured Webcasts
Featured Whitepapers
Featured Reports