arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.30394cs.PLcs.NI

SafeNom:数据感知的微服务策略

SafeNom: Data-Aware Microservice Policies

Karuna Grewal, P. Brighten Godfrey, Justin Hsu

首次发表
浏览论文内容

中文总结 AI 辅助

针对微服务API级联中数据流安全属性监控表达能力有限的问题,提出基于名义语言的SafeNom框架,用名义自动机分布式监控器以黑盒非侵入方式强制执行数据感知策略,延迟仅几毫秒。

中文摘要 AI 辅助

许多基于云的应用被组织为松散耦合的微服务,其中调用某个服务的API会触发跨多个服务的API级联,并导致API参数和输出响应在服务间交换。当前用于监控微服务安全属性的工具,在描述通过API调用的数据流属性方面表达能力有限。为此,我们提出了SafeNom,一个基于名义语言的微服务规范与监控框架。SafeNom策略既能表达API调用的期望顺序,也能表达请求和响应中携带的数据应如何在API之间流动或不应如何流动。策略通过一个基于名义自动机的分布式运行时监控器强制执行,该监控器可以以黑盒和非侵入方式应用,无需访问服务实现,也无需对服务实现进行更改。我们的实验表明,我们的监控器能够高效地强制执行丰富的数据感知属性,同时引入最小的延迟开销,约为几毫秒的量级。

英文摘要

Many cloud-based applications are organized as loosely coupled microservices, where invoking a service's API triggers a cascade of APIs across many services and leads to inter-service exchange of API parameters and output responses. Current tools for monitoring microservice safety properties have limited expressiveness for properties that describe the flow of data through API calls. To this end, we present SafeNom, a specification and monitoring framework for microservices based on nominal languages. SafeNom policies can express both the desired order of API calls and how the data carried in requests and responses should or should not flow between the APIs. Policies are enforced using a nominal automaton-based distributed runtime monitor which can be applied in a blackbox and non-invasive manner, without access to the service implementation and without making changes to the service implementation. Our experiments show that our monitor can efficiently enforce rich data-aware properties while incurring minimal latency overhead, on the order of a few milliseconds.

发表机构

  • Cornell University(康奈尔大学)
  • University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑