Abstract
Methods may detect, terminate and prevent nefarious actions within a computing network. Methods may mine, track and store a data set comprising patterns of normal user activity. Normal user activity may include login times, data access requests per unit time and self-generated network traffic volume per unit time. Methods may create a frequency baseline corresponding to a pattern of normal activity for each user. Methods may monitor the system for deviations in access frequency within the established baseline. Upon identification of deviations, methods may create a security incident and/or electronically relocate a user associated with the security incident within a secured sandbox environment.