Skyler: Static Analysis for Predicting API-Driven Costs in Serverless Applications
Bernardo Ribeiro, Mafalda Ferreira, José Fragoso Santos, Rodrigo Bruno, Nuno Santos
Abstract
Unpredictable costs are a growing concern in serverless computing, where applications rely on cloud APIs with complex tiered pricing models. In many deployments, API calls dominate expenses, and a single overlooked design choice can escalate costs by thousands of dollars. Existing tools fall short: provider calculators need unrealistic manual estimates, and dynamic profilers only work post-deployment.
We present Skyler, a static analysis framework for predeployment cost estimation of API invocations in serverless workflows. Skyler models control flow behavior and pricing semantics to construct symbolic cost expressions using SMT formulas, exposing economic sinks, i.e., code paths where API usage disproportionately impacts cost. This enables developers to identify hotspots and prevent costly architectural errors early. Skyler supports JavaScript-based serverless applications across AWS Lambda, Google Cloud Functions, and Azure Functions, achieving high accuracy (mean absolute percentage error <1% for AWS and Google, 4.5% for Azure).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 49bc8414-3a6f-4710-936a-cb2166b24cb8Builds on15
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- SONIC: Application-aware Data Passing for Chained Serverless ApplicationsAshraf Mahgoub, Karthick Shankar, Subrata Mitra, Ana Klimovic et al.USENIX ATC 2021 · 170 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative TraversalsSoheil Khodayari, Giancarlo PellegrinoUSENIX Security 2021 · 51 citations
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 49 citations
Related papers
- Demystifying Serverless Costs on Public Platforms: Bridging Billing, Architecture, and OS SchedulingChangyuan Lin, Yuanzhi Ma, Mohammad ShahradEuroSys 2026 · 3 citations
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
- λ-trim: Optimizing Function Initialization in Serverless Applications With Cost-driven DebloatingXuting Liu, Spyros Pavlatos, Yuhao Liu, Vincent LiuASPLOS 2025
- Growlithe: A Developer-Centric Compliance Tool for Serverless ApplicationsPraveen Gupta, Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad et al.S&P 2025
- Valve: Securing Function Workflows on Serverless Computing PlatformsPubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace et al.WWW 2020 · 79 citations
