Bridge the Islands: Pointer Analysis for Microservice Systems
Teng Zhang, Yufei Liang, Ganlin Li, Tian Tan, Chang Xu, Yue Li
Abstract
Microservice architecture has revolutionized enterprise software, providing scalability and flexibility by decomposing applications into loosely coupled services. However, this paradigm shift introduces unique challenges for pointer analysis, a foundational static analysis crucial for supporting various client analyses. Existing fundamental analyses, primarily designed for monolithic enterprise applications, fall short in handling complex service communications—such as remote procedure call and message-based communication—and essential programming paradigms, like dependency injection and web endpoint configuration. This paper introduces Micans, the first pointer analysis specifically crafted to address these challenges in microservice systems, capable of constructing comprehensive value flows across services. We extensively evaluated Micans on real-world benchmarks from multiple domains, focusing on its effectiveness in resolving service communications, constructing essential program information like call graphs, and supporting client analyses such as taint analysis. Micans consistently and significantly outperforms state-of-the-art approaches, demonstrating its capacity to handle complex cross-service communications and diverse programming paradigms. These results highlight Micans' potential as a robust foundational analysis, advancing static analysis capabilities to meet the complexities of modern microservices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 41f6106e-d791-46a8-8375-7f6eb37e1b6cCited by top-tier papers1
Ask how each one uses itBuilds on7
- Static analysis of Java enterprise applications: frameworks and caches, the elephants in the roomAnastasios Antoniadis, Nikos Filippakis, Paddy Krishnan, Raghavendra Ramesh et al.PLDI 2020 · 41 citations
- Making pointer analysis more precise by unleashing the power of selective context sensitivityTian Tan, Yue Li, Xiaoxing Ma, Chang Xu et al.OOPSLA 2021 · 39 citations
- Context Sensitivity without Contexts: A Cut-Shortcut Approach to Fast and Precise Pointer AnalysisWenjie Ma, Shengyuan Yang, Tian Tan, Xiaoxing Ma et al.PLDI 2023 · 29 citations
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 26 citations
- MirrorTaint: Practical Non-intrusive Dynamic Taint Tracking for JVM-based Microservice SystemsYicheng Ouyang, Kailai Shao, Kunqiu Chen, Ruobing Shen et al.ICSE 2023 · 11 citations
Related papers
- Detecting Taint-Style Vulnerabilities in Microservice-Structured Web ApplicationsFengyu Liu, Yuan Zhang, Tian Chen, Youkun Shi et al.S&P 2025
- Pointer Analysis for Database-Backed ApplicationsYufei Liang, Teng Zhang, Ganlin Li, Tian Tan et al.PLDI 2025 · 5 citations
- Lifting the veil on Meta's microservice architecture: Analyses of topology and request workflowsDarby Huye, Yuri Shkuro, Raja R. SambasivanUSENIX ATC 2023 · 65 citations
- RPCS hield : Defending Microservices Against Cascading FailuresMilind Chabbi, Sonal Mahajan, Ivan Beschastnikh, René Just et al.SOSP 2026
- Aletheia: Automated Detection of Data Integrity Violations in MicroservicesMafalda Sofia Ferreira, João Ferreira Loff, João Garcia, Rodrigo RodriguesOSDI 2026
