Please check out my latest post for the HP Fortify Blog on defending against Cross-site Request Forgery (CSRF):
[ The Secure Web Series, Part 3: Protecting Against Cross-site Request Forgery (CSRF) ]
...