HTTP (Hypertext Transfer Protocol)

HTTP is the IETF application protocol underlying the web, defined originally in RFC 1945 (1.0), then 7230-7237 (1.1), 7540 (HTTP/2), and 9114 (HTTP/3 over QUIC). HTTP itself transmits data in cleartext, exposing both content and credentials to anyone on the path; this is why all production traffic should run over HTTPS. In 5G the SBA uses HTTP/2 between Network Functions, with mTLS providing transport security and OAuth2 providing authorisation.

Categories: Radio Access NetworkCore NetworkSecurity Controls

HTTP in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place HTTP in the wider telecom-security picture, review Cipher, Inter-Network Function Authentication, OAuth2 in 5G Core, SMPP, NRF Poisoning and 1G — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.