Check router logs or download wireshark to look at incoming traffic (he could be using UDP/TCP/ICMP). However he is probably using a botnet (a group of infected computers ) to ping you, meaning he is not directly part of the attack