%% You should probably cite draft-ietf-i2nsf-framework instead of this I-D. @techreport{merged-i2nsf-framework-04, number = {draft-merged-i2nsf-framework-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-merged-i2nsf-framework/04/}, author = {Edward Lopez and Diego Lopez and Linda Dunbar and John Strassner and Xiaojun Zhuang and Joe Parrott and Ramki Krishnan and Seetharama Rao Durbha}, title = {{Framework for Interface to Network Security Functions}}, pagetotal = 23, year = 2015, month = oct, day = 19, abstract = {This document defines a set of abstractions for guiding the functionality provided by I2NSF. In the design of interfaces to allow for the provisioning of network security functions (NSFs), a critical consideration is to prevent the creation of implied constraints on NSF capability and functionality. This document makes the recommendation that such interfaces be designed from the paradigm of processing packets and flows on the network. NSFs ultimately are packet-processing engines that inspect packets traversing networks, either directly or in the context of sessions in which the packet is associated.}, }