microsoft / binskim
Conditional Complexity

The distribution of complexity of units (measured with McCabe index).

Intro
  • Conditional complexity (also called cyclomatic complexity) is a term used to measure the complexity of software. The term refers to the number of possible paths through a program function. A higher value ofter means higher maintenance and testing costs (infosecinstitute.com).
  • Conditional complexity is calculated by counting all conditions in the program that can affect the execution path (e.g. if statement, loops, switches, and/or operators, try and catch blocks...).
  • Conditional complexity is measured at the unit level (methods, functions...).
  • Units are classified in four categories based on the measured McCabe index: 1-5 (simple units), 6-10 (medium complex units), 11-25 (complex units), 26+ (very complex units).
Learn more...
Conditional Complexity Overall
  • There are 664 units with 10,172 lines of code in units (59.1% of code).
    • 1 very complex units (282 lines of code)
    • 5 complex units (631 lines of code)
    • 21 medium complex units (1,391 lines of code)
    • 46 simple units (1,696 lines of code)
    • 591 very simple units (6,172 lines of code)
2% | 6% | 13% | 16% | 60%
Legend:
51+
26-50
11-25
6-10
1-5
Alternative Visuals
Conditional Complexity per Extension
51+
26-50
11-25
6-10
1-5
cs2% | 6% | 13% | 16% | 60%
c0% | 0% | 0% | 0% | 100%
cpp0% | 0% | 0% | 0% | 100%
Conditional Complexity per Logical Component
primary logical decomposition
51+
26-50
11-25
6-10
1-5
src/BinaryParsers7% | 12% | 9% | 15% | 55%
src/BinSkim.Rules0% | 4% | 17% | 28% | 49%
src/Test.FunctionalTests.BinSkim.Rules0% | 0% | 22% | 3% | 74%
src/BinSkim.Driver0% | 0% | 28% | 0% | 71%
src/BinSkim.Sdk0% | 0% | 0% | 23% | 76%
src/Test.UnitTests.BinaryParsers0% | 0% | 0% | 7% | 92%
src/Test.FunctionalTests.BinSkim.Driver0% | 0% | 0% | 0% | 100%
src/Test.UnitTests.BinSkim.Driver0% | 0% | 0% | 0% | 100%
src/Test.UnitTests.BinSkim.Rules0% | 0% | 0% | 0% | 100%
src/BuildSamples0% | 0% | 0% | 0% | 100%
Most Complex Units
Top 20 most complex units
Unit# linesMcCabe index# params
private void ReadData()
in src/BinaryParsers/ElfBinary/Dwarf/DwarfCompilationUnit.cs
282 65 5
private void LoadDebug()
in src/BinaryParsers/ElfBinary/ElfBinary.cs
106 40 1
public override void AnalyzePortableExecutableAndPdb()
in src/BinSkim.Rules/PERules/BA2024.EnableSpectreMitigations.cs
168 34 1
private static List ReadData()
in src/BinaryParsers/ElfBinary/Dwarf/DwarfLineNumberProgram.cs
160 34 2
public CompilerCommandLine()
in src/BinaryParsers/PEBinary/ProgramDatabase/CompilerCommandLine.cs
120 31 1
internal static List ParseAllCommandLineInfos()
in src/BinaryParsers/ElfBinary/Dwarf/DwarfSymbolProvider.cs
77 30 1
public override void AnalyzePortableExecutableAndPdb()
in src/BinSkim.Rules/PERules/BA2006.BuildWithSecureTools.cs
116 24 1
public static SwitchState GetSwitchState()
in src/BinaryParsers/CommandLineHelper.cs
80 23 5
private static ulong ReadEncodedAddress()
in src/BinaryParsers/ElfBinary/Dwarf/DwarfCommonInformationEntry.cs
82 23 3
private void Verify()
in src/Test.FunctionalTests.BinSkim.Rules/RuleTests.cs
102 23 5
public void AnalyzeNativeBinaryAndPdb()
in src/BinSkim.Rules/PERules/BA2004.EnableSecureSourceCodeHashing.cs
94 22 1
private HashSet GetTestFilesMatchingConditions()
in src/Test.FunctionalTests.BinSkim.Rules/RuleTests.cs
101 18 1
public override void AnalyzePortableExecutableAndPdb()
in src/BinSkim.Rules/PERules/BA2007.EnableCriticalCompilerWarnings.cs
98 17 1
public override void Analyze()
in src/BinSkim.Rules/DwarfRules/BA3003.EnableStackProtector.cs
80 16 1
public static int GetTypeLen()
in src/BinaryParsers/PEBinary/PortableExecutable/PEExtensionMethods.cs
30 16 1
public static object SafePointerToType()
in src/BinaryParsers/PEBinary/PortableExecutable/PEExtensionMethods.cs
25 14 2
private void DumpFile()
in src/BinSkim.Driver/DumpCommand.cs
69 13 2
protected override BinaryAnalyzerContext CreateContext()
in src/BinSkim.Driver/AnalyzeCommand.cs
32 12 5
public override int Run()
in src/BinSkim.Driver/AnalyzeCommand.cs
64 12 1
public override void AnalyzePortableExecutableAndPdb()
in src/BinSkim.Rules/PERules/BA2002.DoNotIncorporateVulnerableDependencies.cs
59 12 1