From a security perspective cc is highly relevant. I use it to get a solid rating of the security aspects of Python code. I use [1] which is solid and proven.
Nice question! Plenty (open) research papers and thesis available the last 40 years -)
Some nice papers: <a href="https://arxiv.org/pdf/2002.07135" rel="nofollow">https://arxiv.org/pdf/2002.07135 , <a href="https://arxiv.org/abs/2411.17343" rel="nofollow">https://arxiv.org/abs/2411.17343, <a href="https://doi.org/10.25300/MISQ/2025/49.1.075" rel="nofollow">https://doi.org/10.25300/MISQ/2025/49.1.075 or see <a href="https://arxiv.org/abs/2411.17343" rel="nofollow">https://arxiv.org/abs/2411.17343
There are many studies about this subject, but mind that complexity in code something different than 'complex' systems. You will need to dive into complexity science , but hard and 'soft' aspects should be taken into account when it comes to cyber security!
Well the first is a discussion without an analysis of existing code, the second is about smart contracts. I'm not convinced that _cyclomatic_ complexity of a function plays a role in security at all. Why:
(a) We have plenty of evidence that buffer overflows etc play a role (caused by using manual memory management), but not so for cyclomatic complexity.
(b) Trying to reduce cyclomatic complexity in one function typically increases the complexity somewhere else, and so is not helping. Often this is just moving stuff around, and sometimes makes things more complex.
runningmike · · focus · HN ↗
[1] <a href="https://nocomplexity.com/documents/codeaudit/complexitycheck.html#complexity-check" rel="nofollow">https://nocomplexity.com/documents/codeaudit/complexitycheck...
thomasmg · · focus · HN ↗
runningmike · · focus · HN ↗
Some nice papers: <a href="https://arxiv.org/pdf/2002.07135" rel="nofollow">https://arxiv.org/pdf/2002.07135 , <a href="https://arxiv.org/abs/2411.17343" rel="nofollow">https://arxiv.org/abs/2411.17343, <a href="https://doi.org/10.25300/MISQ/2025/49.1.075" rel="nofollow">https://doi.org/10.25300/MISQ/2025/49.1.075 or see <a href="https://arxiv.org/abs/2411.17343" rel="nofollow">https://arxiv.org/abs/2411.17343
There are many studies about this subject, but mind that complexity in code something different than 'complex' systems. You will need to dive into complexity science , but hard and 'soft' aspects should be taken into account when it comes to cyber security!
thomasmg · · focus · HN ↗
(a) We have plenty of evidence that buffer overflows etc play a role (caused by using manual memory management), but not so for cyclomatic complexity.
(b) Trying to reduce cyclomatic complexity in one function typically increases the complexity somewhere else, and so is not helping. Often this is just moving stuff around, and sometimes makes things more complex.