SafePar: Monitoring Asynchrony in Microservices

📅 2026-09-27
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of existing mechanisms in capturing the asynchronous parallel structures of microservices and the necessity for non-intrusive compliance monitoring. To this end, it proposes a policy specification and runtime monitoring framework tailored for concurrent microservices. The core innovation lies in introducing the Serial-Parallel Visibility Pushdown Automaton (SPVPA) computational model, which, integrated with policy compilation techniques and service mesh architectures, enables black-box, non-intrusive distributed monitoring of API invocation sequences and serial-parallel topologies. Experimental evaluations demonstrate that the proposed framework supports rich concurrency-aware policy enforcement while introducing only millisecond-level latency overhead, thereby effectively balancing system security with runtime performance.
📝 Abstract
Modern cloud applications are built from loosely-coupled microservices that coordinate through well-defined APIs to service user requests. A single API request often triggers multiple downstream API calls, some executed sequentially and others spawned asynchronously in parallel. To certify safe and secure inter-service interactions in such applications, security and compliance teams must enforce policies not only over nested call/return structure, but also over the parallel structure of an execution: which calls may run concurrently, how many parallel branches can be spawned, and what combination of branch outcomes are allowed. However, existing runtime enforcement mechanisms typically model executions as sequential or purely nested traces, and cannot capture the parallel structure introduced by asynchronous API calls. Furthermore, since application implementations may not be accessible to security and compliance teams, the policy enforcement mechanism should be decoupled from the service implementation. We introduce SafePar, a specification and monitoring framework for policies over concurrent microservice executions. A SafePar policy constrains both the order of API calls and their series-parallel structure. To support seamless deployments, each policy is compiled into a series-parallel visibly pushdown automaton, a new model of computation we propose in this work, that drives a distributed runtime monitor implemented on top of the servicemesh layer. Our technique is blackbox and non-invasive: it requires no access or changes to the service implementation. Our experiments show that SafePar enforces rich concurrency-aware policies while incurring only millisecond-scale latency overhead.
Problem

Research questions and friction points this paper is trying to address.

Microservices
Runtime Enforcement
Asynchronous API Calls
Concurrent Executions
Security Policy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Microservices
Runtime Monitoring
Series-Parallel Visibly Pushdown Automaton
Service Mesh
Concurrency Policies