Security Observability Scope
What BOSS Watches
Detailed breakdown of security indicators observed by the BOSS Service Worker and reported to telemetry.
Network Intelligence
- •Suspicious destination domains & unverified origins
- •Multi-hop cross-origin redirect anomalies
- •High-frequency request bursts & polling loops
- •Origin & referrer header tampering indicators
JavaScript Analysis
- •Dynamic evaluation indicators (eval, Function constructor)
- •Obfuscation patterns & high-entropy string encoding
- •Suspicious base64 / hex payload decoders
- •Dynamic script injection & blob loader patterns
Response Auditing
- •MIME type mismatch anomalies (e.g. JS disguised as image)
- •Missing or stripped security response headers (CSP, CORS)
- •Response body entropy anomalies
- •Token reflection in response query strings
Cache Storage Inspection
- •Suspicious or unregistered cached resources
- •Unexpected CacheStorage volume growth
- •Cache poisoning & stale resource hash mismatch
Runtime Oversight
- •Unhandled global Service Worker promise failures
- •Service Worker lifecycle state transition anomalies
- •Background sync & push payload execution errors
Visibility Matrix
Clear distinction between browser-observable signals and protected engine boundaries.
| Capability | Visibility Status |
|---|---|
| Fetch events & HTTP calls | Observable |
| Cache Storage API | Observable |
| Response metadata & headers | Observable |
| Service Worker lifecycle | Observable |
| IndexedDB metadata | Limited |
| Page DOM tree | Not directly available |
| localStorage API | Not directly available |
| Browser password store | Not available |
| OS process memory | Not available |