SafeNom: Data-Aware Microservice Policies

📅 2026-09-24
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of existing tools in expressing security properties over inter-service data flows within microservice architectures. We propose a specification and monitoring framework grounded in nominal languages that integrates call-sequence and data-flow modeling to support the formal specification of rich, data-aware security policies. Adopting a black-box, non-intrusive design, the approach enables distributed runtime monitoring without requiring source code modifications. Experimental evaluations demonstrate that the framework efficiently enforces complex security properties with only millisecond-level latency overhead, offering a highly expressive yet lightweight security assurance solution for microservices.
📝 Abstract
Many cloud-based applications are organized as loosely coupled microservices, where invoking a service's API triggers a cascade of APIs across many services and leads to inter-service exchange of API parameters and output responses. Current tools for monitoring microservice safety properties have limited expressiveness for properties that describe the flow of data through API calls. To this end, we present SafeNom, a specification and monitoring framework for microservices based on nominal languages. SafeNom policies can express both the desired order of API calls and how the data carried in requests and responses should or should not flow between the APIs. Policies are enforced using a nominal automaton-based distributed runtime monitor which can be applied in a blackbox and non-invasive manner, without access to the service implementation and without making changes to the service implementation. Our experiments show that our monitor can efficiently enforce rich data-aware properties while incurring minimal latency overhead, on the order of a few milliseconds.
Problem

Research questions and friction points this paper is trying to address.

microservices
safety monitoring
data flow
API calls
runtime verification
Innovation

Methods, ideas, or system contributions that make the work stand out.

Microservices
Nominal Languages
Runtime Monitoring
Data-Aware Policies
Distributed Monitor
🔎 Similar Papers
No similar papers found.