The document presents a denial-of-service (DoS) attack detection system utilizing multivariate correlation analysis (MCA) for network traffic characterization, distinguishing between legitimate and illegitimate traffic. This anomaly-based detection approach aims to improve detection accuracy and reduce false alarms while avoiding common pitfalls of misuse-based systems. Evaluated with the KDD Cup 99 dataset, the proposed system demonstrates superior performance against existing methods.