Ben Weintraub

dblp:270/8815 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0002-9527-5888ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Quantifying the Threat of Sandwiching MEV on Jito: A Measurement of Solana's Leading Validator Client
abstract
Solana has emerged as a major blockchain platform providing high throughput and low fees. Like other blockchains, Solana can be attacked via so-called ''Sandwiching'' attacks, where an attacker observes a pending transaction, quickly buys the target cryptocurrency, lets the transaction go through, and then immediately sells it for a profit, skimming that profit from the user who submitted the transaction. While such attacks have been observed by users, they remain underexplored in academic literature due to technical difficulties studying Solana at scale.
Nicole Gerzon, Ben Weintraub, Junbeom In, Alan Mislove, Cristina Nita-Rotaru
IMC2
2025 ProfessorX: Detecting Silent Vulnerabilities in Policy Engine Implementations
abstract
Enterprises that own or handle sensitive resources rely on access control models to protect those resources. NIST has recently standardized a new access control model called Next Generation Access Control (NGAC) and provided a reference implementation. Despite the importance of properly functioning access control systems, little work has been done to verify that the software implementing NGAC properly conforms to the NGAC standard. Prior approaches for finding bugs are either designed to detect fail-stop faults, or model the protocol or software itself, which does not identify discrepancies between software and standards.
Ben Weintraub, Chanyuan Liu, William Enck, Cristina Nita-Rotaru
SACMAT1
2024 Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 Rollups
abstract
The emergence of decentralized finance has transformed asset trading on the blockchain, making traditional financial instruments more accessible while also introducing a series of exploitative economic practices known as Maximal Extractable Value (MEV). Concurrently, decentralized finance has embraced rollup-based Layer-2 solutions to facilitate asset trading at reduced transaction costs compared to Layer-1 solutions such as Ethereum. However, rollups lack a public mempool like Ethereum, making the extraction of MEV more challenging.
Christof Ferreira Torres, Albin Mamuti, Ben Weintraub, Cristina Nita-Rotaru, Shweta Shinde
CCS3
2024 Payout Races and Congested Channels: A Formal Analysis of Security in the Lightning Network
abstract
The Lightning Network, a payment channel network with a market cap of over 192M USD, is designed to resolve Bitcoin's scalability issues through fast off-chain transactions. There are multiple Lightning Network client implementations, all of which conform to the same textual specifications known as BOLTs. Several vulnerabilities have been manually discovered, but to-date there have been few works systematically analyzing the security of the Lightning Network.
Ben Weintraub, Satwik Prabhu Kumble, Cristina Nita-Rotaru, Stefanie Roos
CCS1
2024 Exploiting Temporal Vulnerabilities for Unauthorized Access in Intent-based Networking
abstract
Intent-based networking (IBN) enables network administrators to express high-level goals and network policies without needing to specify low-level forwarding configurations, topologies, or protocols. Administrators can define intents that capture the overall behavior they want from the network, and an IBN controller compiles such intents into low-level configurations that get installed in the network and implement the desired behavior.
Ben Weintraub, Jiwon Kim 0001, Cristina Nita-Rotaru, Hamed Okhravi, Jing (Dave) Tian, Benjamin E. Ujcich
CCS1
2023 MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy
abstract
Commercially-available software defined networking (SDN) technologies will play an important role in protecting the on-premises resources that remain as enterprises transition to zero trust architectures. However, existing solutions assume the entire network resides in a single geographic location, requiring organizations with multiple sites to manually ensure consistency of security policy across all sites. In this paper, we present MSNetViews, which extends a single, globally-defined and managed, enterprise network security policy to many geographically distributed sites. Each site operates independently and enforces a site-specific policy slice that is dynamically parameterized with user location as employees roam between sites. We build a prototype of MSNetViews and show that for an enterprise with globally distributed sites, the average time for policy state to settle after a user roams to a new site is well below two seconds. As such, we demonstrate that multisite organizations can efficiently protect their on-premises network-attached devices via a single global perspective.
Iffat Anjum, Jessica Sokal, Hafiza Ramzah Rehman, Ben Weintraub, Ethan Leba, William Enck, Cristina Nita-Rotaru, Bradley Reaves
SACMAT4
2022 A flash(bot) in the pan: measuring maximal extractable value in private pools
abstract
The rise of Ethereum has lead to a flourishing decentralized marketplace that has, unfortunately, fallen victim to frontrunning and Maximal Extractable Value (MEV) activities, where savvy participants game transaction orderings within a block for profit. One popular solution to address such behavior is Flashbots, a private pool with infrastructure and design goals aimed at eliminating the negative externalities associated with MEV. While Flashbots has established laudable goals to address MEV behavior, no evidence has been provided to show that these goals are achieved in practice.
Ben Weintraub, Christof Ferreira Torres, Cristina Nita-Rotaru, Radu State
IMC1
2022 ShorTor: Improving Tor Network Latency via Multi-hop Overlay Routing
abstract
We present ShorTor, a protocol for reducing latency on the Tor network. ShorTor uses multi-hop overlay routing, a technique typically employed by content delivery networks, to influence the route Tor traffic takes across the internet. In this way, ShorTor avoids slow paths and improves the experience for end users by reducing the latency of their connections while imposing minimal bandwidth overhead. ShorTor functions as an overlay on top of onion routing—Tor’s existing routing protocol—and is run by Tor relays, making it independent of the path selection performed by Tor clients. As such, ShorTor reduces latency while preserving Tor’s existing security properties. Specifically, the routes taken in ShorTor are in no way correlated to either the Tor user or their destination, including the geographic location of either party. We analyze the security of ShorTor using the AnoA framework, showing that ShorTor maintains all of Tor’s anonymity guarantees. We augment our theoretical claims with an empirical analysis. To evaluate ShorTor’s performance, we collect a real-world dataset of over 400,000 latency measurements between the 1,000 most popular Tor relays, which collectively see the vast majority of Tor traffic. With this data, we identify pairs of relays that could benefit from ShorTor: that is, two relays where introducing an additional intermediate network hop results in lower latency than the direct route between them. We use our measurement dataset to simulate the impact on end users by applying ShorTor to two million Tor circuits chosen according to Tor’s specification. ShorTor reduces the latency for the 99thpercentile of relay pairs in Tor by 148ms. Similarly, ShorTor reduces the latency of Tor circuits by 122ms at the 99thpercentile. In practice, this translates to ShorTor truncating tail latencies for Tor which has a direct impact on page load times and, consequently, user experience on the Tor browser.
Kyle Hogan, Sacha Servan-Schreiber, Zachary Newman, Ben Weintraub, Cristina Nita-Rotaru, Srini Devadas
SP4
2022 Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification Documents
abstract
Automated attack discovery techniques, such as attacker synthesis or model-based fuzzing, provide powerful ways to ensure network protocols operate correctly and securely. Such techniques, in general, require a formal representation of the protocol, often in the form of a finite state machine (FSM). Unfortunately, many protocols are only described in English prose, and implementing even a simple network protocol as an FSM is time-consuming and prone to subtle logical errors. Automatically extracting protocol FSMs from documentation can significantly contribute to increased use of these techniques and result in more robust and secure protocol implementations.In this work we focus on attacker synthesis as a representative technique for protocol security, and on RFCs as a representative format for protocol prose description. Unlike other works that rely on rule-based approaches or use off-the-shelf NLP tools directly, we suggest a data-driven approach for extracting FSMs from RFC documents. Specifically, we use a hybrid approach consisting of three key steps: (1) large-scale word-representation learning for technical language, (2) focused zero-shot learning for mapping protocol text to a protocol-independent information language, and (3) rule-based mapping from protocol-independent information to a specific protocol FSM. We show the generalizability of our FSM extraction by using the RFCs for six different protocols: BGPv4, DCCP, LTP, PPTP, SCTP and TCP. We demonstrate how automated extraction of an FSM from an RFC can be applied to the synthesis of attacks, with TCP and DCCP as case-studies. Our approach shows that it is possible to automate attacker synthesis against protocols by using textual specifications such as RFCs.
Maria Leonor Pacheco, Max von Hippel, Ben Weintraub, Dan Goldwasser, Cristina Nita-Rotaru
SP3