Improving Performance of Network Traffic Classification Systems by Cleaning Training Data

In this paper we propose to apply an algorithm for finding out and cleaning mislabeled training sample in an adversarial learning context, in which a malicious user tries to camouflage training patterns in order to limit the classification system performance. In particular, we describe how this algorithm can be effectively applied to the problem of identifying HTTP traffic flowing through port TCP 80, where mislabeled samples can be forced by using port-spoofing attacks.