The invention provides a cross-site request forgery
attack defense method and device, an electronic device and a storage medium, and relates to the technical field of
information security. The method applied to the
client comprises the following steps: generating a parallel session based on a request of a user; determining whether token group updating needs to be carried out or not based on the number of tokens in a first token group stored by the
client; when the token group needs to be updated, obtaining a second token group, and determining a token corresponding to the parallel session in the second token group; the parallel session containing the token corresponding to the parallel session is sent to the
server side, so that the
server side generates a service request based on the parallel session when the token of the parallel session passes
verification, and obtains a service request execution result from the background based on the service request; and receiving a service request execution result returned by the
server. According to the method, available tokens are ensured when a
client needs to perform a session through a token group updating means, and the service stability is improved while cross-site request forgery
attack defense is ensured.