This paper proposes a cross-layer attack detection and defense method that integrates local controller settings, network management, and cloud side control configuration. The significant advantages of this scheme are two folds: on the one hand, it achieves system-level privacy-preserving control to eliminate eavesdropping attacks; on the other hand, it designs a reliable intrusion-tolerant method to eliminate the disruptive impact of stealthy attacks by integrating attack detection-based network blocking defense and open-loop control defense. Note that, the system-level privacy-preserving is achieved based on the output masking, privacy-preserving optimization, and input encryption; the open-loop control defense is achieved based on one-step-ahead predictive interpolating control method. Sufficient numerical comparisons are given to verify the validity of these results.