HTTP (Hypertext Transfer Protocol)

HTTP is the IETF application protocol underlying the web, defined originally in RFC 1945 (1.0), then 7230-7237 (1.1), 7540 (HTTP/2), and 9114 (HTTP/3 over QUIC). HTTP itself transmits data in cleartext, exposing both content and credentials to anyone on the path; this is why all production traffic should run over HTTPS. In 5G the SBA uses HTTP/2 between Network Functions, with mTLS providing transport security and OAuth2 providing authorisation.

Categories: Radio Access NetworkCore NetworkSecurity Controls

HTTP in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place HTTP in the wider telecom-security picture, review OAuth2 in 5G Core, Inter-Network Function Authentication, SMPP, HTTP/2 Security in 5G, Network Exposure Function (NEF) and Service-Based Architecture (SBA) Security: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.