Modeling your App's User Session
github.com
github.com
The ability to revoke sessions is nice, and somewhat related, but it's not the same as preventing replay attacks.
Aside from providing visibility into active sessions, the only other reason I can imagine this being better than signed cookies is if you didn't trust your signing algorithm and wanted to prevent someone from changing parts of your session cookie while retaining a valid signature. As far as I know, the signatures used by Rails and Django have not been called into question.
2. Sign sensitive requests similar to how Amazon does for AWS API requests (http://docs.aws.amazon.com/general/latest/gr/signing_aws_api...) -- just make sure your signature is secure (http://www.daemonology.net/blog/2008-12-18-AWS-signature-ver...).
3. Use client-side certificates by using the HTML5 keygen element to have the browser generate the client's public/private key pair, and then have the server sign the client's public key (http://security.stackexchange.com/questions/27961/should-the...).
4. All of the above.
This isn't perfect, because there will be false positives that log people out fairly often, but it would make session hijacking significantly harder.