arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SafePar:微服务中的异步性监控

SafePar: Monitoring Asynchrony in Microservices

Karuna Grewal, P. Brighten Godfrey, Justin Hsu, Umang Mathur

arXiv 2609.33081首次发表:更新:

发表机构

Cornell University; University of Illinois Urbana-Champaign; National University of Singapore(康奈尔大学; 伊利诺伊大学厄巴纳-香槟分校; 新加坡国立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

SafePar提出一种黑盒监控框架,通过编译策略为串并联可见下推自动机,在服务网格层监控微服务执行的并发结构,实现毫秒级开销的并发感知策略强制。

AI 中文摘要

现代云应用由松耦合的微服务构建而成,这些微服务通过定义良好的API进行协调以服务用户请求。单个API请求通常会触发多个下游API调用,其中一些按顺序执行,另一些则异步并行生成。为了证明此类应用中服务间交互的安全性和可靠性,安全与合规团队不仅需要对嵌套的调用/返回结构实施策略,还需要对执行的并行结构实施策略:哪些调用可以并发运行,可以生成多少个并行分支,以及允许哪些分支结果的组合。然而,现有的运行时强制机制通常将执行建模为顺序或纯嵌套的轨迹,无法捕获异步API调用引入的并行结构。此外,由于安全与合规团队可能无法访问应用程序实现,策略强制机制应与服务实现解耦。我们引入了SafePar,一个针对并发微服务执行策略的规范和监控框架。SafePar策略同时约束API调用的顺序及其串并联结构。为了支持无缝部署,每个策略都被编译成一个串并联可见下推自动机,这是我们在本工作中提出的一种新的计算模型,该自动机驱动在服务网格层之上实现的分布式运行时监控器。我们的技术是黑盒且非侵入性的:它不需要访问或更改服务实现。我们的实验表明,SafePar在强制丰富的并发感知策略的同时,仅产生毫秒级的延迟开销。

英文摘要

Modern cloud applications are built from loosely-coupled microservices that coordinate through well-defined APIs to service user requests. A single API request often triggers multiple downstream API calls, some executed sequentially and others spawned asynchronously in parallel. To certify safe and secure inter-service interactions in such applications, security and compliance teams must enforce policies not only over nested call/return structure, but also over the parallel structure of an execution: which calls may run concurrently, how many parallel branches can be spawned, and what combination of branch outcomes are allowed. However, existing runtime enforcement mechanisms typically model executions as sequential or purely nested traces, and cannot capture the parallel structure introduced by asynchronous API calls. Furthermore, since application implementations may not be accessible to security and compliance teams, the policy enforcement mechanism should be decoupled from the service implementation. We introduce SafePar, a specification and monitoring framework for policies over concurrent microservice executions. A SafePar policy constrains both the order of API calls and their series-parallel structure. To support seamless deployments, each policy is compiled into a series-parallel visibly pushdown automaton, a new model of computation we propose in this work, that drives a distributed runtime monitor implemented on top of the servicemesh layer. Our technique is blackbox and non-invasive: it requires no access or changes to the service implementation. Our experiments show that SafePar enforces rich concurrency-aware policies while incurring only millisecond-scale latency overhead.

Comments27 pages, 6 figure

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑