Forensics: Physical and Logical Size

What is the difference between the physical and logical size shown in Encase/FTK?

All files have a physical and logical size, often the physical size is larger than the logical size, sometimes it is equal to it. But the logical size should never be greater than the physical size, otherwise there is corruption on the file system or something unusual is occurring.

The physical size of a file, is dictated by the minimum number of whole clusters a file needs. e.g If 6 KB file that takes up 1.5 clusters (one cluster = 4kb in this case), it needs 2 clusters for its physical size, and two clusters are 8 KB, therefore the physical size is 8 KB.  Its a bit like transporting people. Whats the minimum number of London Taxis you need to move 6 people? 1.5, but you can’t actually order half a cab, you need 2 cabs, therefore the physical space required to carry 6 people is 8 spaces.

The logical size is how big the file actually is,  in this case 6 kb, the actual size of the file. The difference between the two sizes is known as “file slack“.

For more detailed information on this,  the following articles may be useful:

Video demonstrating file slack.

Clusters

Sectors

What is File Slack


About these ads

3 Responses to “Forensics: Physical and Logical Size”

  1. MFT Slack « Data - Where is it? Says:

    [...] described as the “spare bit” at the end of the file – its the difference between the logical and physical file [...]

  2. Forensics: RAM Slack and File Slack « Data - Where is it? Says:

    [...] in general, refers to the difference between the logical file size and physical file size.  However slack can be broken down into two different areas, RAM slack and File [...]

  3. Forensics: What is the $MFT? « Data – Where is it? Says:

    [...] Physical and Logical Size of the [...]


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.

Join 29 other followers

%d bloggers like this: