The novel Vehicular Cloud Network (VCN) is a close combination of Vehicular Ad hoc Network, Cloud Computing, and Edge Computing. However, VCN is facing the enormous challenge of security and privacy before it is generalized. To address these issues, VCN communication characteristics and security requirements are summarized first. Secondly, the paper conducts an in-depth analysis of the existing security problems and solutions in VCN based on several attack models, including routing, data, identity, DoS, and hostile attacks. And we summarize the security solutions into two categories: security defense measures based on identity authentication and access control, and security protection measures based on traffic detection and anomaly detection. Thirdly, this paper proposes a reliable VCN security architecture consisting of three types of clouds: vehicular, edge, and central clouds. Moreover, the VCN architecture combines a Vehicle Intrusion Detection and Prevention System with a Vehicular Cloud Security Management Platform to ensure the security of VCN. Last but not least, some open issues worth investigating are discussed.