BSidesNYC 0x04 CFP Information
Huxley Barbee (BSidesNYC)
BSides NYC 2023 (0x04) · Day 1 · CFP Info
Overview
This presentation by Huxley Barbee of BSidesNYC serves as the official Call for Papers (CFP) for the fourth annual BSides NYC conference, scheduled for October 19th, 2024, at John Jay College. Far from a traditional technical deep dive into a specific vulnerability or research, this talk is a vital announcement outlining the myriad opportunities for security professionals, entrepreneurs, and educators to contribute to and participate in one of New York City's premier grassroots cybersecurity events. It details the various submission tracks—including technical sessions, a resurrected entrepreneur track, hands-on workshops, and dedicated villages—providing essential guidance for prospective speakers and participants.

Key moments
- 0:00 Conference introduction, date, location, and contacts
- 0:48 Technical tracks CFP: topics, talk lengths, submission
- 2:10 Entrepreneur track: sharing insights on building security companies
- 3:40 Entrepreneur track: business proposal pitches to investors
- 4:40 Workshop CFP: requirements, duration, and submission
- 6:00 Call for Villages: how to participate
BSidesNYC 2024 Call for Papers: A Gateway to Community-Driven Security Innovation
Speakers: Huxley Barbee, BSidesNYC
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=Xrs316WCi-8
Overview
This presentation by Huxley Barbee of BSidesNYC serves as the official Call for Papers (CFP) for the fourth annual BSides NYC conference, scheduled for October 19th, 2024, at John Jay College. Far from a traditional technical deep dive into a specific vulnerability or research, this talk is a vital announcement outlining the myriad opportunities for security professionals, entrepreneurs, and educators to contribute to and participate in one of New York City's premier grassroots cybersecurity events. It details the various submission tracks—including technical sessions, a resurrected entrepreneur track, hands-on workshops, and dedicated villages—providing essential guidance for prospective speakers and participants.
The importance of this CFP extends beyond mere logistical announcements; it is the foundational mechanism through which BSides NYC curates its content, ensuring a diverse, relevant, and cutting-edge program for its attendees. By actively soliciting contributions across the entire spectrum of information security, from offensive and defensive techniques to strategic program management and career development, the conference aims to foster a collaborative environment where knowledge sharing and community building are paramount. This talk is crucial for anyone looking to share their expertise, gain exposure for a new security venture, or simply understand the breadth of topics that will shape the upcoming BSides NYC experience.
Background
▶ Watch: Conference introduction, date, location, and contacts (0:00)
The BSides movement, born from a desire for more accessible, community-driven security conferences, has grown into a global phenomenon. Each BSides event, including BSides NYC, embodies a unique spirit of collaboration, knowledge exchange, and a commitment to providing high-quality content in an informal, inclusive setting. These conferences are typically organized by volunteers and rely heavily on the community's willingness to share expertise, making the Call for Papers a cornerstone of their operational model. The CFP process is critical for identifying emerging trends, showcasing innovative research, and ensuring that the conference program reflects the current challenges and advancements within the cybersecurity landscape.
BSides NYC, now entering its fourth iteration, has established itself as a significant platform within the New York City information security community. Its continued success is predicated on its ability to attract a broad array of speakers addressing diverse topics. The conference's structured approach, with dedicated tracks for Red Team, Blue Team, and "Other Colors" of the information security spectrum, reflects a comprehensive understanding of the multifaceted nature of modern cybersecurity. This categorization ensures that attendees with varied interests, from offensive security practitioners to defensive strategists and those focused on governance or career development, will find valuable content tailored to their needs. The reintroduction of the entrepreneur track, in particular, highlights BSides NYC's commitment to supporting the vibrant startup ecosystem within the security industry, providing a unique platform for innovation and business development alongside technical discourse.
Key Findings
▶ Watch: Entrepreneur track: sharing insights on building security companies (2:10)
While this talk itself is not a technical presentation with research findings, it unveils several significant "findings" in the form of announcements and opportunities for the BSides NYC community, shaping the conference's structure and content for 2024. These key revelations are pivotal for anyone considering participation:
- Expanded Talk Lengths: For the 2024 conference, BSides NYC is introducing 25-minute talk slots in addition to the traditional 55-minute sessions. This offers greater flexibility for speakers, allowing for more concise presentations on specific topics or providing an entry point for first-time speakers to gain conference experience without the commitment of a longer session. This expansion is a direct response to community feedback and the desire to maximize content diversity.
- Resurrection of the Entrepreneur Track: A major announcement is the reintroduction of the Entrepreneur Track, a unique feature designed to support New York City's burgeoning security startup scene. This track is divided into two distinct submission types:
- Veteran Sessions: Aimed at experienced entrepreneurs who have successfully built or grown security companies, these sessions provide a platform to share personal insights, lessons learned, and practical advice relevant to the security community. This offers invaluable mentorship opportunities for aspiring founders.
- Business Proposal Pitches: This innovative format allows individuals with new security ideas to present a one-page PDF business proposal live to a panel of investors. This provides critical exposure, feedback, and potential networking opportunities for early-stage security ventures, directly fostering innovation within the community.
- Dedicated Hands-On Workshops: The conference will once again feature Workshops, emphasizing practical, hands-on learning experiences. These two-hour sessions require a strong interactive component and present specific infrastructure constraints, such as the assumption that attendees will bring their own laptops with wireless adapters, but nothing else about their operating system or pre-installed software. This encourages creative and accessible workshop design, ensuring broad participation.
- Dedicated Villages Room: A specific room will be allocated for Villages, providing a dedicated space for community groups, special interest areas, or interactive exhibits. This fosters focused engagement and allows various sub-communities within the security landscape to have a physical presence and dedicated activities at the conference.
- Broad Spectrum of Technical Topics: The CFP explicitly welcomes submissions across the entire "information security color wheel," encompassing a vast array of topics from offensive security (e.g., penetration testing, exploit development) to defensive strategies (e.g., vulnerability management, incident response, malware analysis), and broader areas like threat intelligence, social engineering, security program management, secure coding, privacy policy, risk management, open source intelligence (OSINT), digital forensics, and career development. This commitment to diversity ensures a comprehensive and well-rounded technical program.
- Key Deadlines and Submission Process: The CFP officially opens on April 17th and closes on July 19th. All submissions, whether for technical talks, entrepreneur sessions, or pitches, are managed through the BSides NYC website portal (bsidesnyc.org), with specific track selections required. Workshops and Villages, however, require direct email submissions. These dates and processes are crucial for all prospective contributors to adhere to.
These announcements collectively define the structure and opportunities available at BSides NYC 2024, making this CFP talk a critical informational resource for the community.
Technical Deep Dive
▶ Watch: Entrepreneur track: business proposal pitches to investors (3:40)
It is important to clarify that this specific presentation, given by Huxley Barbee, is a Call for Papers announcement and not a technical deep dive into a specific vulnerability, tool, or research project. Therefore, it does not contain detailed technical content, code examples, protocol analyses, or architectural discussions that would typically constitute a "Technical Deep Dive" section in an article about a research talk.
However, the talk does provide an exhaustive list of the technical domains and topics that BSides NYC is actively seeking for its technical tracks. These categories themselves offer a comprehensive overview of the current landscape of cybersecurity concerns and research areas. By examining the types of submissions encouraged, we can infer the depth and breadth of technical content expected at the conference:
- Vulnerability Management: Talks in this area would typically delve into the systematic process of identifying, assessing, and remediating security weaknesses in systems and applications. This could include discussions on automated scanning tools, vulnerability prioritization frameworks (e.g., CVSS, EPSS), patch management strategies, the integration of vulnerability data into DevSecOps pipelines, or the challenges of managing vulnerabilities in complex enterprise environments. Speakers might share insights into managing CVE databases, effective reporting, or leveraging threat intelligence to contextualize vulnerability severity.
- Threat Intelligence: This domain encompasses the collection, processing, and analysis of information about potential or actual threats to an organization. Technical talks might cover the use of STIX/TAXII for sharing threat intelligence, the integration of open-source and commercial threat feeds, the development of custom indicators of compromise (IOCs), or techniques for operationalizing intelligence to enhance defensive capabilities. This could also include discussions on MITRE ATT&CK framework mapping and its application in intelligence analysis.
- Social Engineering: While often perceived as a human-centric attack vector, technical talks in this area often explore the tools and techniques used to craft convincing phishing campaigns, vishing attacks, or pretexting scenarios. This might involve discussions on OSINT techniques for target profiling, the psychology behind successful social engineering, or technical countermeasures like email authentication (SPF, DKIM, DMARC) and user awareness training platforms.
- Security Program Management: This topic focuses on the strategic and operational aspects of building and maintaining an effective security posture. Technical discussions could involve frameworks like NIST CSF, ISO 27001, or CIS Controls, detailing their implementation, challenges, and success metrics. Talks might cover risk assessment methodologies, security budgeting, compliance automation, or the integration of security into broader business processes.
- Secure Coding: Essential for preventing vulnerabilities at their source, talks here would likely focus on best practices for developing secure software. This could include discussions on specific language-level security features, the use of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools, threat modeling in the software development lifecycle (SDLC), or secure design patterns (e.g., OWASP Top 10 mitigations).
- Privacy Policy: While often legalistic, the implementation of privacy policies (e.g., GDPR, CCPA) has significant technical implications. Discussions could revolve around privacy-enhancing technologies (PETs), data anonymization techniques, secure data storage and access controls, or the technical challenges of maintaining data subject rights (e.g., right to erasure, data portability).
- Risk Management: This involves identifying, assessing, and mitigating security risks. Technical presentations might explore quantitative or qualitative risk assessment methodologies, the use of GRC (Governance, Risk, and Compliance) platforms, or the development of risk registers and mitigation strategies. This could also include discussions on supply chain risk management and third-party vendor assessments.
- Penetration Testing: A core offensive security discipline, talks would detail methodologies, tools (e.g., Metasploit, Nmap, Burp Suite), and techniques for identifying and exploiting vulnerabilities in systems, networks, and applications. This could include specific exploitation techniques, red team engagements, or the ethical considerations and reporting aspects of penetration testing.
- Open Source Intelligence (OSINT): Technical talks on OSINT would focus on advanced techniques and tools for gathering information from publicly available sources. This might include discussions on specialized search engines, data scraping, social media analysis, geolocation techniques, or the ethical boundaries and legal implications of OSINT collection.
- Malware Analysis: This involves dissecting malicious software to understand its functionality, origin, and potential impact. Technical deep dives could cover static analysis (e.g., IDA Pro, Ghidra), dynamic analysis (e.g., sandboxing, debugging), reverse engineering techniques, or the identification of specific malware families (e.g., ransomware, trojans, rootkits) and their evasion tactics.
- Incident Response: Critical for mitigating the impact of security breaches, talks would focus on the processes, tools, and methodologies for detecting, analyzing, containing, eradicating, and recovering from security incidents. This could include discussions on Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) solutions, forensic analysis techniques, or building effective incident response playbooks.
- Digital Forensics: This specialized field involves the recovery and investigation of material found in digital devices, often in relation to computer crime. Technical presentations might detail techniques for acquiring forensic images, analyzing file systems (e.g., NTFS, EXT4), memory forensics, network forensics, or the use of specific forensic tools (e.g., Autopsy, Volatility Framework).
- Exploit Development: A highly technical and specialized area, talks would delve into the process of creating functional exploits for identified vulnerabilities. This could include discussions on memory corruption techniques (e.g., buffer overflows, use-after-free), Return-Oriented Programming (ROP), bypassing security mitigations (e.g., ASLR, DEP), or developing proof-of-concept code for zero-day vulnerabilities.
- Career Development in Information Security: While not purely technical, talks here often provide insights into technical skill pathways, certifications (e.g., OSCP, CISSP), mentorship, and navigating the various technical roles within the security industry. This could include discussions on building a technical portfolio, interview strategies for security roles, or transitioning between different technical specializations.
By inviting submissions across these diverse and deeply technical domains, BSides NYC ensures that its conference program will offer a rich tapestry of cutting-edge research, practical applications, and strategic insights for all attendees. The CFP is the mechanism to gather the raw material for these technical discussions.
Demo / Proof of Concept
▶ Watch: Workshop CFP: requirements, duration, and submission (4:40)
As this presentation by Huxley Barbee is a Call for Papers announcement for the BSides NYC 2024 conference, it does not include any live demonstrations or proof-of-concept (PoC) exploits. The purpose of this talk is to inform prospective speakers and participants about the submission process, available tracks, and deadlines. The actual technical demonstrations and PoCs will be presented by chosen speakers at the conference itself, based on the submissions received through this CFP.
Defensive Implications
▶ Watch: Call for Villages: how to participate (6:00)
Similar to the "Technical Deep Dive" and "Demo / Proof of Concept" sections, this Call for Papers announcement does not present specific defensive implications or strategies. Its role is to lay the groundwork for a conference where such implications will be discussed, debated, and disseminated.
However, the very nature of BSides NYC and the broad scope of its CFP implicitly offer significant defensive implications for the cybersecurity community. By soliciting talks across a wide array of topics—from vulnerability management and incident response to secure coding and threat intelligence—the conference aims to equip defenders with the latest knowledge and tools. For instance, talks on exploit development or penetration testing directly inform blue teams about the methods adversaries might employ, allowing them to harden their defenses proactively. Discussions on malware analysis provide insights into new threat vectors and mitigation techniques. The Entrepreneur Track could lead to the development of new defensive security products or services, while Workshops offer hands-on training for practical defensive skills. In essence, the CFP acts as a funnel, gathering the collective wisdom of the security community to ultimately strengthen defensive postures across the industry.
Key Takeaways
- BSides NYC 2024 Date & Location: The fourth annual conference will be held on October 19th, 2024, at John Jay College.
- CFP Open & Close Dates: The Call for Papers opened on April 17th and will close on July 19th, emphasizing a clear window for submissions.
- Diverse Technical Tracks: The conference features dedicated tracks for Red Team, Blue Team, and "Other Colors" of information security, covering a vast range of topics including vulnerability management, threat intelligence, social engineering, secure coding, incident response, and exploit development.
- New Talk Lengths: Speakers can choose between 25-minute and 55-minute talk slots, offering increased flexibility for presentation styles and content depth.
- Resurrected Entrepreneur Track: This track offers two distinct opportunities: Veteran Sessions for experienced founders to share insights, and Business Proposal Pitches for new ideas to be presented live to a panel of investors.
- Hands-On Workshops & Villages: The conference will host two-hour, hands-on workshops (with specific infrastructure constraints) and a dedicated room for Villages, encouraging interactive learning and community engagement.
- Submission Process: Technical and Entrepreneur track submissions are via the bsidesnyc.org website portal; Workshops and Villages require direct email to [email protected] with "Workshop" or "Village" in the subject line.
About the Speaker(s)
Huxley Barbee is a representative of BSidesNYC, serving as a key organizer for the conference. In this capacity, Barbee is instrumental in outlining the vision, structure, and opportunities for participation in the annual BSides NYC event. His role involves communicating critical information such as the Call for Papers details, track categories, submission guidelines, and key deadlines to the broader cybersecurity community. As a voice for BSides NYC, Barbee embodies the grassroots, community-driven spirit of the BSides movement, working to foster an inclusive and educational environment for security professionals and enthusiasts.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
This is a conference logistics announcement — CFP dates, track descriptions, submission URLs. It is not a talk. There is nothing to review, score, or recommend watching.
Heather Calloway (CISO) — PASS
This is a conference logistics announcement, not a security talk. There is no research, no argument, no risk finding, and nothing to evaluate from a governance or defender standpoint.