Intrusion detection system (IDS) and intrusion prevention system (IPS) tend to be expensive and complicated. In AWS, you
can go for much simpler solution - WAF. But that requires you to use Application Load Balancer or CloudFront. But even
with WAF, you have to manage a list IP addresses of attackers that should be blocked. Or, if you only ever need to block
single IPs for short periods of time, NACLs may be a much easier option! Here’s a walkthrough on how you can implement a
terribly simple (yet very powerful) intrusion detection and prevention in AWS with Lambda and DynamoDB Streams for a web
application.