you don't even really need intrusion detection systems if there's not really a place someone can get in
you prevent it by just not designed a "run arbitrary code" endpoint in your system, more or less
if you're working in a language that's not c or c++, then you just don't need to worry *that* much about an attacker getting code execution