Safeguard is a Double-edged Sword: Denial-of-service Attack on Large Language Models