arXiv · 2609.30394
SafeNom: Data-Aware Microservice Policies
Abstract
Many cloud-based applications are organized as loosely coupled microservices, where invoking a service's API triggers a cascade of APIs across many services and leads to inter-service exchange of API parameters and output responses. Current tools for monitoring microservice safety properties have limited expressiveness for properties that describe the flow of data through API calls. To this end, we present SafeNom, a specification and monitoring framework for microservices based on nominal languages. SafeNom policies can express both the desired order of API calls and how the data carried in requests and responses should or should not flow between the APIs. Policies are enforced using a nominal automaton-based distributed runtime monitor which can be applied in a blackbox and non-invasive manner, without access to the service implementation and without making changes to the service implementation. Our experiments show that our monitor can efficiently enforce rich data-aware properties while incurring minimal latency overhead, on the order of a few milliseconds.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Karuna Grewal, P. Brighten Godfrey, Justin Hsu. 2026-09-24. SafeNom: Data-Aware Microservice Policies. https://arxiv.org/abs/2609.30394
Cite the original work for its findings. Save a collection to share your selection of sources.