Security Observability Scope

What BOSS Watches

Detailed breakdown of security indicators observed by the BOSS Service Worker and reported to telemetry.

Network Intelligence

  • •Suspicious destination domains & unverified origins
  • •Multi-hop cross-origin redirect anomalies
  • •High-frequency request bursts & polling loops
  • •Origin & referrer header tampering indicators

JavaScript Analysis

  • •Dynamic evaluation indicators (eval, Function constructor)
  • •Obfuscation patterns & high-entropy string encoding
  • •Suspicious base64 / hex payload decoders
  • •Dynamic script injection & blob loader patterns

Response Auditing

  • •MIME type mismatch anomalies (e.g. JS disguised as image)
  • •Missing or stripped security response headers (CSP, CORS)
  • •Response body entropy anomalies
  • •Token reflection in response query strings

Cache Storage Inspection

  • •Suspicious or unregistered cached resources
  • •Unexpected CacheStorage volume growth
  • •Cache poisoning & stale resource hash mismatch

Runtime Oversight

  • •Unhandled global Service Worker promise failures
  • •Service Worker lifecycle state transition anomalies
  • •Background sync & push payload execution errors

Visibility Matrix

Clear distinction between browser-observable signals and protected engine boundaries.

CapabilityVisibility Status
Fetch events & HTTP callsObservable
Cache Storage APIObservable
Response metadata & headersObservable
Service Worker lifecycleObservable
IndexedDB metadataLimited
Page DOM treeNot directly available
localStorage APINot directly available
Browser password storeNot available
OS process memoryNot available