Set a cookie on the client when it hits your site before it sends any Ajax requests.
Then confirm the cookie when serving Ajax.
Or, alternatively, you can only make an Ajax POST request. Thus, they are subject to the same policy of origin.
This will break the whole calm ideology.
http://en.wikipedia.org/wiki/Same_origin_policy