Documente Academic
Documente Profesional
Documente Cultură
Livia Nguyen
CFR105
Explanation:
Logical File Size is the actual number of bytes occupied by the file data.
Physical File Size is the number of clusters used by the file on the disk.
The equation for calculating file slack is physical size logical size = file slack.
The first step that I have to do is to figure out how many clusters are on the drive by diving the
file size by the cluster size. Round the number to the next number, if the answer has left over
when dividing. For example: 5100/40961=1.25, then that will give you 2 clusters.
I then create a visual look of what the drive would look like with the number that I got from the
calculation.
To calculate for the total byte of slack, I subtract the file byte the file bytes by of the total bytes
cluster slack. The total bytes of slack are the space left over from the end of the data of a file to
The file slack is all of the byte of the full sector within the total bytes of slack. For example:
there are 6 full sectors, then we multiple it by 512 bytes and that give us the total of 3072 bytes
of file slack.
The RAM slack is the slack between the end of the logical file and the rest of the sector, and to
calculate the RAM slack simply subtract the file slack by the total byte of slack. For example:
We were given 3092 total bytes of slack and 3072 file slack, then subtract it will give us 20 bytes
of RAM slack.
Equation:
1. On an NTFS drive with 512 byte sectors, and 8 sectors per cluster with the size of a cluster is
4096 bytes, if a file is 5100 bytes long calculate the following three numbers:
Cluster 1 Cluster 2
512 512
RAM slack
512
512 512
512 512
File Slack
512 512
512 512
512 512
512 512
B. RAM slack
3092-3072= 20 byte
2. A 600-byte file is stored on a hard disk with 4 sectors per cluster and 512-bytes sector,
B. RAM slack
3. A 198-byte file is stored on a standard floppy disk with a 512-bytes sector, calculate the
B. RAM slack
512x0= 0 byte
The result show that there is no file slack and the total bytes of slack is the RAM slack.
4. A 1024-byte file is stored on a standard floppy disk with a 512-bytes sector, calculate the
Cluster 1 Cluster 2
512 512
1024-1024= 0 byte
B. RAM slack
RAM & FILE SLACK 5
0-0= 0 byte
512x0= 0 byte
The result shows that there is no slack space on the disk , that mean that there are no file slack or
RAM slack on the disk, and that all the sector is filled with file content. However, if the user
decides to delete all of the content of this file, it will appear to be unallocated, but the content of
the file remains on the disk and can be recovered by using forensic tool.
5. A 291,341-byte file is stored on a hard disk with a 8 sectors per cluster and 4096-bytes sector,
B. RAM slack
512x0= 0 byte
There are no file slacks left on this hard disk and the slack space on the hard disk is the RAM
slack
RAM & FILE SLACK 6
Reference
Carrier, B. (2011). File System Forensic Analysis. Upper Saddle River, NJ: Addison-Wesley.
Forensics: RAM Slack and File Slack. (2009, April 25). Retrieved June 22, 2017, from
https://whereismydata.wordpress.com/2009/04/25/forensics-ram-slack-and-file-slack/