Using the HttpServletRequest and ServletRequest objects, there are methods to determine the "forwarding" URL, and IP and machine name (I forget the precise methods, but take a look at the API docs) - so you could test these - if they are not yours, then dump the request.