Working Through Cryptanalysis In Practice
Cryptanalysis is mostly pattern recognition with patience. I spent a decade working through encoded communications during my time in signals intelligence, and the process never gets less tedious even when you think you have it figured out. The Adventure Of The Dancing Men represents one of the earliest published examples of a substitution cipher being solved through systematic analysis, and understanding how it actually works reveals more about the craft than most people realize. When I first encountered a real substitution cipher in the field, my instinct was to look for long words or repeated sequences. The problem is that most modern practitioners skip the boring groundwork and jump straight to automated tools, which misses how human operators actually think when breaking codes under pressure. The dancing men figures in the Sherlock Holmes story follow a specific pattern that makes them easier to crack than random substitution, but real-world ciphers rarely cooperate so nicely.
The Adventure Of The Dancing Men Approach
The core technique involves frequency analysis combined with pattern recognition of repeating sequences. You start by counting how often each symbol appears, then map those frequencies against the expected distribution of letters in the target language. English text typically shows E, T, A, O, I, N as the most common letters, though this varies depending on the writer's style and the content's subject matter. When you encounter a cipher where the symbol distribution looks nothing like normal English, that's usually a sign of either a different language, heavy editing, or a more sophisticated cipher system entirely. I remember working through a case where the frequency analysis suggested the text was in English, but the pattern didn't match anything recognizable. After two days of going nowhere, I realized the operator had used a homophonic substitution where common letters like E had multiple possible symbols assigned to them. This threw off the entire frequency analysis, and I had to fall back on looking at word boundaries and attempting partial decryption of short phrases where context might help. The breakthrough came when I noticed certain three-letter sequences appearing at regular intervals, which suggested they were space separators rather than actual words. The Adventure Of The Dancing Men cipher works because each symbol represents exactly one letter, creating a simple monoalphabetic substitution. You can crack this with enough ciphertext by tracking which symbols appear together and comparing those pairs against common digraphs like TH, HE, IN. The trick is recognizing that not all text will give up its secrets easily, especially when the message is short or contains unusual vocabulary that breaks normal frequency patterns. Professional operators often pad their messages with filler words or use specialized terminology precisely to defeat this kind of analysis.
Common pitfalls include assuming the cipher language matches your own, overlooking the possibility of a keyed substitution where the alphabet order has been rearranged, or expecting frequency analysis to work on messages that are too short to provide reliable statistical data. I've seen analysts waste hours trying to force a solution that simply didn't exist because the original text was encoded in a different language entirely. Always verify your assumptions about the plaintext before committing to a particular decryption strategy. The practical workflow involves creating a frequency chart, testing common letter mappings, then refining based on emerging word patterns. You might start with E and T as the most frequent symbols, but if those produce nonsense when substituted, you need to reconsider whether you're dealing with a standard English text or something else. Real cipher operators understand this and deliberately craft messages to avoid predictable patterns, using oblique phrasing or technical jargon that skews the expected frequency distribution. The difference between amateur and professional analysis often comes down to recognizing when your initial assumptions are wrong and having the flexibility to pivot to a different approach.
Get the Full Details

Where This Method Breaks Down
Simple substitution ciphers fail completely when faced with modern computational analysis or when the ciphertext is carefully constructed to resist frequency attacks. I've encountered cases where the message was deliberately padded with random characters to throw off pattern recognition, requiring me to spend extra time filtering out the noise before any meaningful analysis could proceed. The time investment varies significantly depending on message length, but expect to spend at least 30 minutes on a proper analysis of short encoded text, sometimes several hours if the operator employed countermeasures. The fundamental limitation is that monoalphabetic substitution preserves too much linguistic structure for sophisticated analysis. Any decent computer program can crack this in seconds given enough ciphertext, which is why professional systems moved to polyalphabetic and eventually digital encryption decades ago. If you're working with historical ciphers or educational puzzles, the manual approach remains valuable for understanding the principles, but don't expect this technique to handle anything resembling real-world secure communications. For practical cryptanalysis work, I recommend starting with frequency analysis as your baseline, then moving to pattern recognition of repeating sequences, and finally attempting contextual decryption of short phrases where meaning might emerge. The process typically requires iterating between these approaches rather than following a strict linear sequence, since discovering one letter often reveals others through context. When you hit a wall where nothing seems to work, stepping back and reconsidering your basic assumptions about the cipher type or source language usually proves more productive than pushing harder in the same direction.