‹ BackHN Continuity

Thread

Cyclomatic Complexity in C#

87 points · 29 comments · gone35

  1. runningmike · · focus · HN ↗
    From a security perspective cc is highly relevant. I use it to get a solid rating of the security aspects of Python code. I use [1] which is solid and proven.

    [1] <a href="https:&#x2F;&#x2F;nocomplexity.com&#x2F;documents&#x2F;codeaudit&#x2F;complexitycheck.html#complexity-check" rel="nofollow">https:&#x2F;&#x2F;nocomplexity.com&#x2F;documents&#x2F;codeaudit&#x2F;complexitycheck...

    1. thomasmg · · focus · HN ↗
      Is there research that show if and how much a low complexity improves security?
      1. ozim · · focus · HN ↗
        Weird question to ask, that is pretty obvious.

        Worst things happen always when 2 or more systems are combined because each system might be simple on its own, yet a combination is always much more complex.

        1. bunderbunder · · focus · HN ↗
          It’s not obvious to me because cyclomatic complexity is not a straightforward proxy for the number of systems that are being combined.

          It’s also the case that some of the most common sources of vulnerabilities, such as SQL injection, introduce no additional cyclomatic complexity. Heck, buffer overflows are good for your cyclomatic complexity - those array bounds checks are all extra branches.

          1. pixl97 · · focus · HN ↗
            Buffer overflow checks are really only going to be a linear growth in CC. It&#x27;s when things move towards exponential growth or higher that it gets really easy to introduce flaws of many kinds.

            Now, it&#x27;s probably not a direct correlation. I&#x27;d think security bugs are more likely from programmers that unintentionally raise CC without really realizing it. Aka, overreaching their own knowledge when simpler structures are avaliable.

            1. bunderbunder · · focus · HN ↗
              Sure. It’s just that there’s also so much research that has found that cyclomatic complexity is theoretically ill-founded, and that it tends to underperform other ways of measuring complexity. Most notably, just counting lines of code. (Not per function, in total.)

              Here’s an oldie but goodie: <a href="https:&#x2F;&#x2F;cs.du.edu&#x2F;~snarayan&#x2F;sada&#x2F;teaching&#x2F;COMP3705&#x2F;lecture&#x2F;p1&#x2F;cycl-1.pdf" rel="nofollow">https:&#x2F;&#x2F;cs.du.edu&#x2F;~snarayan&#x2F;sada&#x2F;teaching&#x2F;COMP3705&#x2F;lecture&#x2F;p...

              I’ve personally had better success thinking of it as more of a measure of readability than of quality.

        2. BoiledCabbage · · focus · HN ↗
          &gt; Weird question to ask, that is pretty obvious.

          For something the the prior statement it is never a weird question to ask of there actually evidence of this or just it seems like it should be true so we believe it.

          There are tons of things that seem like they would obviously be true, but it turns out they aren&#x27;t.

          1. [deleted] · · focus · HN ↗

            [deleted]

          2. ozim · · focus · HN ↗
            System is more complex based on possible states it can have or inputs&#x2F;outputs.

            That is just maths here working. Two systems combined always will have more states and inputs&#x2F;outputs.

            There is nothing to check here as it can be proven purely by maths.

            Complex systems having more attack surface are obviously less secure.

            They might be less interesting for attackers if they have to scan huge attack surface like IPv6 vs IPv4 but no one is claiming IPv6 network is more secure.

            1. anon48293 · · focus · HN ↗
              No. Watch the simple made easy talk.

              Just more I&#x2F;O isn’t more complicated nor a bigger risk. More entanglement is more complicated.

            2. Rexxar · · focus · HN ↗

                &gt; That is just maths here working
              
              No this is just numerology here, it&#x27;s meaningless.
            3. bunderbunder · · focus · HN ↗
              Cyclomatic complexity is funny math, though. The article demonstrates how. They took a single function that makes state changes to an object, and scattered that logic across four different functions that make the same set of state changes. That’s all. This had adverse impact on the complexity of the system - the logic and behavior of the top level function are the same. It’s just as stateful and has just as many linearly independent code paths. They just got shuffled around to game the way that cyclomatic complexity treats function calls.

              But in the process they created three additional functions to call. That means the overall system has more possible code paths, and introduces a need to think about what happens if they are ever called from somewhere other than the original entry point. Introducing ways to screw things up that did not previously exist is not reducing complexity and it is not increasing maintainability.

              Your insistence that this somehow managed complexity is exactly why I wrote the top level comment cautioning people about how they interpret cyclomatic complexity. If you don’t understand what it’s actually measuring - not complexity, not really - then it will mislead you into bad decisions.

        3. saghm · · focus · HN ↗
          I&#x27;d argue that assuming something is obvious without any empirical validation is the root of a huge number of misconceptions that humanity has historically had. There&#x27;s a reason science suddenly started moving a lot faster after we moved past Aristotle and started measuring things in experiments.
      2. runningmike · · focus · HN ↗
        Nice question! Plenty (open) research papers and thesis available the last 40 years -)

        Some nice papers: <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2002.07135" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2002.07135 , <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.17343" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.17343, <a href="https:&#x2F;&#x2F;doi.org&#x2F;10.25300&#x2F;MISQ&#x2F;2025&#x2F;49.1.075" rel="nofollow">https:&#x2F;&#x2F;doi.org&#x2F;10.25300&#x2F;MISQ&#x2F;2025&#x2F;49.1.075 or see <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.17343" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;abs&#x2F;2411.17343

        There are many studies about this subject, but mind that complexity in code something different than &#x27;complex&#x27; systems. You will need to dive into complexity science , but hard and &#x27;soft&#x27; aspects should be taken into account when it comes to cyber security!

        1. thomasmg · · focus · HN ↗
          Well the first is a discussion without an analysis of existing code, the second is about smart contracts. I&#x27;m not convinced that _cyclomatic_ complexity of a function plays a role in security at all. Why:

          (a) We have plenty of evidence that buffer overflows etc play a role (caused by using manual memory management), but not so for cyclomatic complexity.

          (b) Trying to reduce cyclomatic complexity in one function typically increases the complexity somewhere else, and so is not helping. Often this is just moving stuff around, and sometimes makes things more complex.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.