이번 보안감사는 다섯 달 동안 두 DJI 기체·조종기 조합을 software·hardware·RF에서 적대적으로 시험한 시점 한정 평가다. OnDefend는 2025년 10월부터 2026년 3월까지 Air 3S·RC 2와 Matrice 4E·RC Plus 2 Enterprise를 시험하고 critical·high·medium 등급 발견을 보고하지 않았다. 동시에 확인되지 않은 것도 분명하다. 모든 DJI 제품, 향후 firmware, cloud 계정과 운영망 전체가 영구히 안전하다는 보증은 아니다.

발표가 실제로 다룬 네 개 system
DJI의 공식 보안평가 발표는 consumer Air 3S+RC 2와 enterprise Matrice 4E+RC Plus 2 조합을 대상으로 했다고 밝힌다. consumer unit은 소매점에서, enterprise unit은 dealer stock에서 조달해 표준 미국 유통품을 반영했다고 설명한다.
시험 범위는 DJI Fly·Pilot 2 app의 static·dynamic 분석, network traffic, local data mode, certificate 검증 우회·privilege escalation·jailbreak 시도, PCB·silicon 수준 점검, supply-chain integrity와 1MHz~6GHz RF scan·replay·jamming·injection을 포함한다. 공개 summary는 방법 범주를 주지만 모든 test case, firmware hash와 raw trace를 공개하지 않는다.
평가 비용을 DJI가 승인·의뢰했고 OnDefend가 독립 수행했다는 구조도 함께 기록한다. 독립은 시험 수행의 조직적 분리를 뜻하지만 funding, scope negotiation과 공개 선택의 영향을 없애는 단어가 아니다. report 원문과 executive summary, vendor press release를 구분한다.
결과 장부에는 ‘0’보다 조건을 적는다
| 결과 | 공개된 근거 | 유효 범위 | 남는 질문 |
|---|---|---|---|
| critical·high·medium 0 | 5개월 adversarial assessment summary | 시험한 4개 system·version·기간 | 전체 test case·severity rubric·raw evidence |
| low-risk 10·observation 13 | app config·session·wireless hardening 중심 | 당시 발견과 remediation 협의 | 각 issue 상세·수정 release·재시험 |
| 미국 밖 전송 증거 없음 | 관측 connection이 미국 infrastructure로 resolve | 시험 network·mode·time window | 다른 계정·지역·future endpoint |
| backdoor·원격접근 없음 | jailbreak·firmware modification 시도 저항 | 평가한 attack path | 모든 unknown vulnerability 부재 |
| 숨은 RF channel 없음 | 1MHz~6GHz scan과 신호 attribution | 시험 hardware·lab condition | 다른 band·update·physical tamper |
‘zero findings’라고 줄이면 10 low-risk와 13 observations를 지운다. 반대로 low-risk가 있었다는 이유만으로 critical compromise라고 부풀리면 severity를 왜곡한다. finding마다 affected component, exploit precondition, impact, fix owner, release와 retest를 추적한다.
DJI Trust Center의 audit 기록은 2017년 이후 여러 평가를 한곳에 모은다. 축적된 audit는 반복 검증의 증거지만 서로 다른 product·version·method를 한 번의 종합 인증으로 합칠 수 없다.
하드웨어·software·RF를 함께 본 기술적 의미
drone security는 app traffic만 막는 문제가 아니다. signed firmware와 secure boot가 약하면 controller·aircraft code가 바뀔 수 있고, radio link의 인증·replay 저항이 약하면 command·telemetry가 영향을 받을 수 있다. PCB·component inspection은 undocumented path와 supply-chain tamper 가설을, RF scan은 covert emission 가설을 시험한다. 서로 다른 RF·network·device 기록을 같은 공격 장면으로 재구성하려면 hardware timestamp와 시간동기가 먼저 맞아야 한다.
network test는 standard mode와 local data mode에서 endpoint, encryption, certificate validation과 session을 본다. ‘미국 밖 전송 없음’은 시험한 device·account·DNS·network 조건의 observation이다. cloud operator, CDN·routing과 regional policy가 바뀌면 다시 측정해야 한다.
보안평가 설계를 읽을 때는 NIST SP 800-115 기술 보안시험 가이드가 제시하는 planning, execution, findings analysis와 mitigation 흐름처럼 scope·rules of engagement·evidence와 remediation을 확인한다. DJI 평가가 이 문서의 인증을 받았다는 뜻은 아니며, 독자가 point-in-time test의 구성요소를 판단하는 비교 기준으로만 쓴다.
평가 뒤에도 변하지 않은 위험
firmware와 app update는 새 code와 dependency, endpoint를 가져온다. 시험 기간 뒤 release는 기존 결론의 자동 연장이 아니다. hardware revision, supplier lot, chip mask·board change와 controller accessory도 scope를 바꾼다. high-assurance operator는 approved baseline과 새 version의 delta를 계산하고 위험에 따라 full 또는 focused retest를 수행한다.
운영망의 identity·access, account compromise, phone·tablet hygiene, key 관리와 incident response도 제품 penetration test와 다르다. 제품에 backdoor가 없더라도 약한 비밀번호나 overprivileged account로 fleet data가 노출될 수 있다. enterprise deployment는 asset inventory, network segmentation, log monitoring과 revocation을 자체 통제한다.
정책 판단도 기술 summary 하나로 끝나지 않는다. FCC Covered List 등 공급망 정책은 공개 technical finding 외의 법적·국가안보 요소를 포함할 수 있다. audit 결과는 중요한 evidence지만 규제 지정의 자동 철회나 모든 조직의 procurement approval을 뜻하지 않는다.
다음 확인은 수정 release와 반복성이다
가장 먼저 볼 것은 low-risk 10건의 disposition이다. issue ID, affected version, 수정 여부, 새 firmware·app release, retest result와 remaining acceptance를 확인한다. ‘향후 release에서 처리’라는 상태와 이미 수정·배포·검증된 상태를 나눈다.
- 시험한 aircraft·controller·app·firmware·hardware revision과 hash를 확인한다.
- threat model, excluded component·cloud·mobile OS와 physical access 가정을 기록한다.
- severity rubric과 10 low-risk·13 observations의 disposition을 추적한다.
- network·local data mode·RF·firmware·supply chain 결과를 별도 evidence로 유지한다.
- software·firmware·hardware·endpoint 변경 뒤 delta review와 재시험을 수행한다.
- 제품 test와 operator IAM·network·incident response를 독립 통제로 관리한다.
- vendor-funded independent assessment의 원문·summary와 policy claim을 구분한다.
좋은 후속 증거는 다시 ‘0’이라는 큰 숫자가 아니다. 버전이 바뀔 때 test harness를 반복할 수 있고, 발견이 수정 release와 readback에 연결되며, scope 밖 위험을 운영자가 자체 통제로 닫는 것이다. 2026 감사는 강한 snapshot이지만 그 snapshot을 살아 있는 assurance program으로 이어야 한다.
현장에서 다시 확인할 질문
이 평가 결과는 DJI 사용기관의 구매 판단에 바로 적용되나요?
시험한 Air 3S·RC 2와 Matrice 4E·RC Plus 2 Enterprise의 해당 version을 검토하는 기관에는 직접 관련된다. 다른 기체·controller·지역 cloud·future firmware는 범위 밖일 수 있다. 기관은 자체 threat model, 법규·procurement policy와 운영망 통제를 함께 적용해야 한다.
중·고위험 발견이 0이면 DJI drone은 해킹할 수 없다는 뜻인가요?
아니다. 정해진 기간·제품·version·attack path에서 해당 severity 발견이 없었다는 뜻이다. 공개되지 않은 취약점, 새 update, 계정탈취, operator network와 supply-chain change는 남는다. low-risk 발견의 수정·재시험과 지속적 version assessment가 필요하다.
자료 마지막 확인: 2026년 8월 26일